Database Install/Upgrade/Opatch (MOSC)

MOSC Banner

Oracle DB 18 - Apache Log4j 2.x < 2.17.0 DoS - pgx-webapp-2.5.1-wls.war

Hi, our security team ask to fix a vulnerability of Oracle:

"The version of Apache Log4j on the remote host is 2.x < 2.3.1 / 2.13.2 / 2.17.0. It is, therefore, affected by a denial of service vulnerability" - CVE-2021-45105

The vulnerability is on:

/app/oracle/product/18.0.0/dbhome_1/md/property_graph/pgx/server/pgx-webapp-2.5.1-wls.war

Installed version : 2.9.0 - Fixed version : 2.12.3 / 2.17.0

/app/oracle/product/18.0.0/dbhome_1/md/property_graph/pgx/server/pgx-webapp-2.5.1.war

Installed version : 2.9.0 - Fixed version : 2.12.3 / 2.17.0


The server has installed Enterprise Manager Cloud Control 13c with Oracle Database version 18.0.


Are those version of pgx-webapps vulnerable?


Thanks

Howdy, Stranger!

Log In

To view full details, sign in to My Oracle Support Community.

Register

Don't have a My Oracle Support Community account? Click here to get started.

Category Leaderboard

Top contributors this month

New to My Oracle Support Community? Visit our Welcome Center

MOSC Help Center