Is there an official stance on CVE-2021-4104
Our vulnerability management team recently scanned our OIM infrastructure with the Kenna Security tool and it flagged the servers as vulnerable to CVE-2021-4104, recommending to upgrade to log4j 2.
I see all the other log4j remediation bulletins, which I applied before the scan, but they do not reference this specific CVE, nor can I find anything else about it specifically in a MOS search.
I want to know if Support has an official stance on CVE-2021-4104 as it relates to OIM, WLS, and/or FMW so I can respond accordingly to our vulnerability management team.
Thank you,