PeopleTools and Lifecycle Management - PSFT (MOSC)

MOSC Banner

Cannot mitigate log4j issue on HCMPUM46

I perform a installation of HCMPUM46 on Windows using native installation. After installation I ran a log4j detector on the drive I installed it on.

The tool indicated that I had a vulnerability with the following below.

T:\psoft\HR92U046\db\oracle-server\19.3.0.0\suptools\tfa\release\tfa_home\jlib\tfa.war!/WEB-INF/lib/log4j-core-2.9.1.jar contains Log4J-2.x  >= 2.0-beta9 (< 2.10.0) VULNERABLE

I'm not seeing this full path to mitigate the issue. Can someone advise how to correct this issue.


Thanks AG

Howdy, Stranger!

Log In

To view full details, sign in to My Oracle Support Community.

Register

Don't have a My Oracle Support Community account? Click here to get started.

Category Leaderboard

Top contributors this month

New to My Oracle Support Community? Visit our Welcome Center

MOSC Help Center