Oracle Weblogic Server (MOSC)

MOSC Banner

Log4j remediation on WebLogic 12.2.1.4

Hi Team,

We are frequently getting log4j remidation for below particular file on WebLogic v12.2.1.4. Also we have applied latest patch for 12.2.1.4 recently. But again below file reporting as vulnerable in cyber security scan. Could you please suggest what action do we need to take here? Do we need to do consider this is a false alert cause we have applied below latest patch?


applied latest patch:-12.2.1.4.220105

WebLogic version:-12.2.1.4

OS Version:-RHEL7

JDK:-Java SE 8 Update 321


Below path and file reporting:-

Path             : /opt/bea/weblogic/oracle_common/modules/thirdparty/log4j-2.11.1.jar

 Installed version : 2.11.1

 Fixed version    : 2.12.3


Regards,

Howdy, Stranger!

Log In

To view full details, sign in to My Oracle Support Community.

Register

Don't have a My Oracle Support Community account? Click here to get started.

Category Leaderboard

Top contributors this month

New to My Oracle Support Community? Visit our Welcome Center

MOSC Help Center