OEM Agent 13.5.0 RU 21 & CVE-2022-42889
Hi,
I've update our OEM agent from RU 20 to RU 21 and now our security scan tool has detected CVE-2022-42889 and it points to this file:
d:\oracle_agent\agent_13.5.0.0.0.patch_storage\36005330_feb_17_2024_02_25_17\files\oracle.sysman.top.agent\13.5.0.0.0\oracle.sysman.agent.symbol\jlib\commons-text-1.8.jar
I tried to remove it by using:
opatch util DeleteInactivePatches
(cleans up oneoffs and .patch_storage directories)
but the oem agent opatch does not know the util DeleteInactivePatches options :-(
What is the best way to remove this jar file? cve-2022-42889 is a critical one so our security are asking to resolve this asap.