log4j 1.2.13 in libraries being flagged
Hello in the latest version of sql developer (23.1.1.345.2114) their is a log4j-1.2.13.jar present. I am trying to fix findings that keep reporting this as a vulnerability. In our case the sql developer instance is under the oracle reports (12.2.1.4) server home.
The documentation on MOSC indicate that installing the latest version of sql dveloper into the home should resolve the vulnerability, how ever it looks like the jar is still present and is being flagged.
Is there any other options I can try? do we need to have the copy of sql developer in the reports home if users don't use it? can we just remove the old jar?