Enterprise Manager Security (MOSC)

MOSC Banner

OEM Agent 13.5.0 RU 21 & CVE-2022-42889

Hi,

I've update our OEM agent from RU 20 to RU 21 and now our security scan tool has detected CVE-2022-42889 and it points to this file:

d:\oracle_agent\agent_13.5.0.0.0.patch_storage\36005330_feb_17_2024_02_25_17\files\oracle.sysman.top.agent\13.5.0.0.0\oracle.sysman.agent.symbol\jlib\commons-text-1.8.jar

I tried to remove it by using:

opatch util DeleteInactivePatches

(cleans up oneoffs and .patch_storage directories)

but the oem agent opatch does not know the util DeleteInactivePatches options :-(

What is the best way to remove this jar file? cve-2022-42889 is a critical one so our security are asking to resolve this asap.

Howdy, Stranger!

Log In

To view full details, sign in to My Oracle Support Community.

Register

Don't have a My Oracle Support Community account? Click here to get started.

Category Leaderboard

Top contributors this month

New to My Oracle Support Community? Visit our Welcome Center

MOSC Help Center