Log4j remediation on WebLogic 12.2.1.4
Hi Team,
We are frequently getting log4j remidation for below particular file on WebLogic v12.2.1.4. Also we have applied latest patch for 12.2.1.4 recently. But again below file reporting as vulnerable in cyber security scan. Could you please suggest what action do we need to take here? Do we need to do consider this is a false alert cause we have applied below latest patch?
applied latest patch:-12.2.1.4.220105
WebLogic version:-12.2.1.4
OS Version:-RHEL7
JDK:-Java SE 8 Update 321
Below path and file reporting:-
Path : /opt/bea/weblogic/oracle_common/modules/thirdparty/log4j-2.11.1.jar
Installed version : 2.11.1
Fixed version : 2.12.3
Regards,