Skip to Main Content

Oracle Database Discussions

Announcement

For appeals, questions and feedback about Oracle Forums, please email oracle-forums-moderators_us@oracle.com. Technical questions should be asked in the appropriate category. Thank you!

Is Oracle 19c affected by Log4j Vulnerability

GeekDBAMay 24 2022

Hi Team,
We have Oracle 19c(standard version) PROD database running on Windows server.
In recent security scans it is detected that Oracle 19c software path has vulnerable Log4j files.
They are
i)(c:\app\oracle\product\19.0.0\dbhome_1\suptools\tfa\release\tfa_home\jlib\log4j-core-2.9.1.jar)
ii)(c:\app\oracle\product\19.0.0\dbhome_1\md\property_graph\lib\log4j-core-2.11.0.jar)

Is it true that the software is Vulnerable.
Can someone please shed some light on this topic.
https://support.oracle.com/knowledge/Support%20Tools/2847142_1.html
https://support.oracle.com/knowledge/Oracle%20Cloud/2827611_1.html
https://blogs.oracle.com/security/post/log4j-vulnerabilities

Thanks and Regards
Venkat

Comments

Processing

Post Details

Added on May 24 2022
1 comment
1,322 views