Is Oracle planning to update unsupported versions of log4j (1.x) to supported (2.x) versions?
Weekly Nessus scans of our environment are returning a critical vulnerability related to the current unsupported Log4j version currently in use in our Oracle EBS products. These unsupported (1.x) versions persist despite applying all quarterly released Critical Patch Updates.
Does Oracle plan to release updates that include the most recent versions of Log4j to address this vulnerability?
Example scan output:
Apache Log4j Unsupported Version Detection
Upgrade to a version of Apache Log4j that is currently supported.
Upgrading to the latest versions for Apache Log4j is highly recommended as intermediate
versions / patches have known high severity vulnerabilities and the vendor is updating