PeopleTools and Lifecycle Management - PSFT (MOSC)

MOSC Banner

Does patch 8.58.17 include mitigation steps for CVE-2021-44228 and CVE-2021-45046 ?

Hello,

Doc ID 2828073.1 contains mitigation steps for  CVE-2021-44228 and CVE-2021-45046 for log4j.

Do the log4j-core*.jar files delivered with Patch 8.58.17 are already updated (no JndiLookup.class class file in the log4j-core*.jar located in PS_HOME)?

Do the log4j-core*.jar files created when deploying PIA with Patch 8.58.17 are already updated (no JndiLookup.class class file in the log4j-core*.jar located in PS_CFG_HOME/webserv).

I reviewed the January 2022 Crital Patch Update report but above CVE are only listed for WebLogic, not for PeopleTools.

Thank you,

Best Regards,

Hervé

Howdy, Stranger!

Log In

To view full details, sign in to My Oracle Support Community.

Register

Don't have a My Oracle Support Community account? Click here to get started.

Category Leaderboard

Top contributors this month

New to My Oracle Support Community? Visit our Welcome Center

MOSC Help Center