Qualys is flagging EOL/Obsolete Software: Apache Log4j 1.X Detected in the Oracle EBS version 12.2
I require clarification regarding the current Apache Log4j implementation and associated security measures for our risk assessment. Specifically, Ineed to understand why the system has not been upgraded from Log4j version 1.x to 2.x, and whether this is due to dependency conflicts or other technical constraints. If the system must remain on version 1.x due to compatibility requirements, I need confirmation of the security mitigation steps that have been implemented to address known vulnerabilities. This includes whether JNDI lookup functionality has been disabled, if the JMSAppender component has been removed or disabled, and what other hardening measures are in place.