Database Install/Upgrade/Opatch (MOSC)

MOSC Banner

Patch 33559893 includes 2.9 Log4j Jarfiles?

edited Feb 9, 2022 5:47PM in Database Install/Upgrade/Opatch (MOSC) 1 comment

Combo OJVM Release Update 12.2.0.1.220118 and Database Release Update 12.2.0.1.220118 Patch 33559893

This patch really includes 2.9 Log4j Jarfiles. After all the CVEs 4 weeks ago, where we manually cleaned up all existing hosts, I cannot beleive, that Oracle now delivers a patchset which includes all the vulnerable Jarfiles agiain, so that we are forced to use the mitigation again, after patching.

I would appreciate, if some could point me to a bug about this issue, which probvalby already exists, so that I am not forced to create an SR.


TIA,

Gerrit

Howdy, Stranger!

Log In

To view full details, sign in to My Oracle Support Community.

Register

Don't have a My Oracle Support Community account? Click here to get started.

Category Leaderboard

Top contributors this month

New to My Oracle Support Community? Visit our Welcome Center

MOSC Help Center