Oracle DB 18 - Apache Log4j 2.x < 2.17.0 DoS - pgx-webapp-2.5.1-wls.war
Hi, our security team ask to fix a vulnerability of Oracle:
"The version of Apache Log4j on the remote host is 2.x < 2.3.1 / 2.13.2 / 2.17.0. It is, therefore, affected by a denial of service vulnerability" - CVE-2021-45105
The vulnerability is on:
/app/oracle/product/18.0.0/dbhome_1/md/property_graph/pgx/server/pgx-webapp-2.5.1-wls.war
Installed version : 2.9.0 - Fixed version : 2.12.3 / 2.17.0
/app/oracle/product/18.0.0/dbhome_1/md/property_graph/pgx/server/pgx-webapp-2.5.1.war
Installed version : 2.9.0 - Fixed version : 2.12.3 / 2.17.0
The server has installed Enterprise Manager Cloud Control 13c with Oracle Database version 18.0.
Are those version of pgx-webapps vulnerable?
Thanks