ksukumaran (Customer) to rsaSFDCadmin (RSA): asked a question.

Log4j files - Vulnerability alert
Hi Everyone,

Following Log4j files are notified by vulnerability tool -

Location of file - /u01/app/19.0.0/grid/suptools/tfa/release/tfa_home/jlib

files - log4j-api-2.9.1.jar
log4j-core-2.9.1.jar

We recently upgraded to 7.5.2 from 7.5.0 to overcome this issue. But still we
could see the above log4j files exists in the above mentioned location. Last
access dates of these files are years ago. The recent upgrade also didnt touch
these file I think. Not sure whether we can delete this file manually. Any
suggestions from anyone?

  • Please open a Support Case to report the potential vulnerability for
    investigation. Make sure to provide the vulnerability tool's scan report in
    the Case. Thank you!
    Selected as Best
  • Please open a Support Case to report the potential vulnerability for
    investigation. Make sure to provide the vulnerability tool's scan report in
    the Case. Thank you!
    Selected as Best