Why does Nessus still report Apache log4j vulnerabilities after patching?
After installing all current FMW 12.2.1.4 patches (36086980,36187026,36155700), Nessus scanning still reports the Apache Log4j vulnerability.
The version is still reported as 2.11.1 and should be no lower than 2.12.2., based on path below:
MW_HOME/oracle_common/modules/thirdparty/log4j-2.11.1.jar.
There are also subsequent reports for other log4j vulnerabilities of lower severity due to the version reported.
Nessus plug-in numbers for this are :155999,156327,156057, and 156183.
What can be done to further remediate or eliminate the vulnerability being reported?