Enterprise Manager Generic (MOSC)

MOSC Banner

Apache Log4j 1.2 JMSAppender OEM 13.5 agents

Our tenable nessus vulnerability scanner found the following:

Apache Log4j 1.2 JMSAppender Remote Code Execution (CVE-2021-4104) (156103)

affected files of the oem agent 13.5 are:

  • agent_13.5.0.0.0/ocm/jlib/jlib/log4j-core.jar
  • agent_13.5.0.0.0/sysman/jlib/log4j-core.jar

we have applied the latest agent patch 13.5.0.10 (34611817)

is there anything else to update/remove these files?

Howdy, Stranger!

Log In

To view full details, sign in to My Oracle Support Community.

Register

Don't have a My Oracle Support Community account? Click here to get started.

Category Leaderboard

Top contributors this month

New to My Oracle Support Community? Visit our Welcome Center

MOSC Help Center