OEM 13.4 and cve vulnerabilties
Hi,
Our security engineers scan our servers for log4j issues. It started with CVE-2021-44228. but now they scan for several other vulnerabilities and OEM (Enterpise Manager) has a versy bad score. The scanner is Logpresso CVE-2021-44228 Vulnerability Scanner 2.9.1 (2022-02-03). And this is the (very long list) of vulnerabilities: [CVE-2022-23305(8.1)] /prod/app/middleware_13.4/wlserver/server/lib/consoleapp/APP-INF/lib/log4j-1.2.17-16.jar contains log4j-1.2.17 [CVE-2022-23305(8.1)] /prod/app/middleware_13.4/wlserver/modules/clients/com.oracle.webservices.wls.jaxws-wlswss-client.jar contains log4j-1.2.17 [CVE-2021-4104(7.5), CVE-2022-23302(6.6), CVE-2022-23305(8.1), CVE-2022-23307(8.1)] /prod/app/middleware_13.4/ocm/repeater/jlib/log4j-core.jar contains log4j-1.2.17 [CVE-2021-4104(7.5), CVE-2022-23302(6.6), CVE-2022-23305(8.1), CVE-2022-23307(8.1)] /prod/app/middleware_13.4/ocm/repeater/ears/OCMRepeater.ear [CVE-2021-4104(7.5), CVE-2022-23302(6.6), CVE-2022-23305(8.1), CVE-2022-23307(8.1)] /prod/app/middleware_13.4/oracle_common/log4j-core.jar contains log4j-1.2.17 [CVE-2019-17571(9.8), CVE-2021-4104(7.5), CVE-2022-23302(6.6), CVE-2022-23305(8.1), CVE-2022-23307(8.1)] /prod/app/middleware_13.4/plugins/oracle.sysman.db.oms.plugin_13.4.1.0.0/archives/emdb.war [CVE-2017-5645(9.8)] /prod/app/middleware_13.4/plugins/oracle.sysman.db.oms.plugin_13.4.1.0.0/archives/emdb.war [CVE-2022-23305(8.1)] /prod/app/middleware_13.4/oracle_common/modules/com.bea.core.apache.log4j.jar contains log4j-1.2.17 [CVE-2019-17571(9.8), CVE-2021-4104(7.5), CVE-2022-23302(6.6), CVE-2022-23305(8.1), CVE-2022-23307(8.1)] /prod/app/middleware_13.4/oracle_common/modules/oracle.owasp/com-bea-core-apache-log4j.jar contains log4j-1.2.17 [CVE-2021-4104(7.5), CVE-2022-23302(6.6), CVE-2022-23305(8.1), CVE-2022-23307(8.1)] /prod/app/middleware_13.4/oracle_common/ccr/lib/log4j-core.jar contains log4j-1.2.17 [CVE-2021-4104(7.5), CVE-2022-23302(6.6), CVE-2022-23305(8.1), CVE-2022-23307(8.1)] /prod/app/middleware_13.4/oracle_common/ccr/inventory/core.jar [CVE-2019-17571(9.8), CVE-2021-4104(7.5), CVE-2022-23302(6.6), CVE-2022-23305(8.1), CVE-2022-23307(8.1)] /prod/app/middleware_13.4/bi/modules/oracle.bi.datadirect.odbc/8.0.2/tools/schematool.jar contains log4j-1.2.15 [CVE-2019-17571(9.8), CVE-2021-4104(7.5), CVE-2022-23302(6.6), CVE-2022-23305(8.1), CVE-2022-23307(8.1)] /prod/app/middleware_13.4/bi/modules/oracle.bithirdparty/apache/log4j.jar contains log4j-1.2.14 [CVE-2019-17571(9.8), CVE-2021-4104(7.5), CVE-2022-23302(6.6), CVE-2022-23305(8.1), CVE-2022-23307(8.1)] /prod/app/middleware_13.4/bi/modules/oracle.bi.publisher/thirdparty/activemq-all.jar
1