Are Oracle client 11.2 and Oracle client 12 vulnerable with the Log4j security issue?

Viewed 14486

I'm reading about the security issue with Log4j and I understand this product is affected by the vulnerability. But is Oracle client 11.2 and 12affected by this issue?

I couldn't find if those products use any Log4j dependency or any documentation saying that those products are affected or not.

Are other Oracle products affected by this problem? Where I can check which dependencies those clients use?

3 Answers

The link below will let you know which Oracle products need patches for Log4j.

Here is a section of the document that shows a list of Oracle products not required for a Log4j 2 patch.

5.0 Oracle products not requiring patches

At this point in time, Oracle doesn’t believe the following products to be affected by vulnerability CVE-2021-44228:

  • Application Testing Suite [Product ID 4622]
  • Argus Analytics [Product ID 9171]
  • Argus Mart [Product ID 10383]
  • Banking Digital Experience [Product ID 12605]
  • Berkeley DB [Product ID 2051]
  • Commerce Platform [Product ID 9348]
  • Commerce Service Center [Product ID 9351]
  • Communications Converged Application Server [Product ID 5382]
  • Communications EAGLE FTP Table Base Retrieval [Product ID 11116]
  • Communications Network Integrity [Product ID 4491]
  • Communications Order and Service Management [Product ID 2270]
  • CRF Submit Requestor [Product ID 9641]
  • Database Gateway for APPC [Product ID 774]
  • Demantra Demand Management [Product ID 2100]
  • Enterprise Data Quality [Product ID 9464]
  • Enterprise Manager for MySQL Database [Product ID 11166]
  • Exalytics Software [Product ID 9736]
  • FLEXCUBE Direct Banking [Product ID 9111]
  • Health Insurance Claims Management Data Marts [Product ID 9313]
  • Health Insurance Data Management [Product ID 10643]
  • Healthcare Data Repository [Product ID 9161]
  • JD Edwards EnterpriseOne Deployment Server [Product ID 4781]
  • JD Edwards EnterpriseOne Enterprise Server [Product ID 4781]
  • JD Edwards EnterpriseOne Enterprise Server Platform Pack [Product ID 4781]
  • JD Edwards EnterpriseOne Server Manager [Product ID 4781]
  • JD Edwards World [Product ID 4839]
  • Mobile Application Framework [Product ID 11055]
  • MySQL Server [Product ID 8478]
  • Oracle Access Manager / Webgates [Product ID 5565]
  • Oracle Access Manager [Product ID 5565]
  • Oracle Application Express [Product ID 1348]
  • Oracle Audit Vault and Database Firewall [Product ID 9749]
  • Oracle Big Data Spatial and Graph [Product ID 11528]
  • Oracle Blockchain Cloud Service [Product ID 13444]
  • Oracle Business Intelligence Enterprise Edition [Product ID 2025]
  • Oracle Business Intelligence Publisher [Product ID 1479]
  • Oracle Client [Product ID 5]
  • Oracle Coherence [Product ID 2545]
  • Oracle Commerce Guided Search/Oracle Commerce Experience Mgr [Product ID 9633]
  • Oracle Communications Calendar Server [Product ID 8494]
  • Oracle Communications Contacts Server [Product ID 10696]
  • Oracle Communications Control Plane Monitor [Product ID 10764]
  • Oracle Communications EAGLE [Product ID 10768]
  • Oracle Communications EAGLE Application Processor [Product ID 11122]
  • Oracle Communications EAGLE Element Management System [Product ID 11125]
  • Oracle Communications EAGLE LNP Application Processor [Product ID 11118]
  • Oracle Communications Fraud Monitor [Product ID 10763]
  • Oracle Communications LSMS [Product ID 11114]
  • Oracle Communications MetaSolv Solution [Product ID 2267]
  • Oracle Communications Operations Monitor [Product ID 10761]
  • Oracle Communications Session Border Controller [Product ID 10750]
  • Oracle Communications User Data Repository [Product ID 11108]
  • Oracle Database (not exploitable) [Product ID 5] [See MOS Note 2796575.1]
  • Oracle Database Appliance [Product ID 9435]
  • Oracle Database Global Service Manager [Product ID 5]
  • Oracle Directory Server Enterprise Edition [Product ID 8512]
  • Oracle Documaker [Product ID 5477]
  • Oracle Enterprise Operations Monitor [Product ID 10762]
  • Oracle Enterprise Session Border Controller [Product ID 10757]
  • Oracle Enterprise Telephony Fraud Monitor [Product ID 13804]
  • Oracle Exadata Storage Server Software [Product ID 2546]
  • Oracle Fail Safe [Product ID 843]
  • Oracle Forms [Product ID 45]
  • Oracle Global Lifecycle Management Repository Creation Utility [Product ID 12746]
  • Oracle GoldenGate [Product ID 5757]
  • Oracle GoldenGate for HP Nonstop [Product ID 13046]
  • Oracle Health Insurance Claims Management [Product ID 9307]
  • Oracle Health Insurance Claims Management Web Services [Product ID 9311]
  • Oracle Health Insurance Disbursements and Collections [Product ID 9308]
  • Oracle Health Insurance Long Term Care [Product ID 9394]
  • Oracle Health Insurance Policy Administration [Product ID 9306]
  • Oracle Health Insurance Policy Administration Data Marts [Product ID 9312]
  • Oracle Health Insurance Policy Administration Web Services [Product ID 9310]
  • Oracle Health Sciences Argus Safety [Product ID 5710]
  • Oracle Health Sciences Clinical Development Analytics [Product ID 5563]
  • Oracle Health Sciences InForm [Product ID 9636]
  • Oracle Hospitality RES 3700 [Product ID 11596]
  • Oracle Hospitality Simphony [Product ID 11594]
  • Oracle Hospitality Simphony First Edition [Product ID 11591]
  • Oracle HTTP Server [Product ID 1042]
  • Oracle Internet Directory [Product ID 355]
  • Oracle Key Vault [Product ID 10221]
  • Oracle MapViewer [Product ID 1215]
  • Oracle MiniCluster S7-2 Engineered System [Product ID 12598]
  • Oracle NoSQL Database [Product ID 13373]
  • Oracle Retail Advanced Inventory Planning [Product ID 1785]
  • Oracle Retail Data Model [Product ID 2538]
  • Oracle SD-WAN Aware [Product ID 13941]
  • Oracle SD-WAN Edge [Product ID 13940]
  • Oracle Secure Backup [Product ID 1522]
  • Oracle Service Architecture Leveraging Tuxedo (SALT) [Product ID 5435]
  • Oracle SOA Suite [Product ID 1162]
  • Oracle StorageTek Tape Analytics [Product ID 10085]
  • Oracle TimesTen In-Memory Database [Product ID 1870]
  • Oracle Tuxedo Application Rehosting Workbench [Product ID 8485]
  • Oracle Tuxedo Mainframe Adapter for OSI TP [Product ID 5439]
  • Oracle VM [Product ID 4455]
  • Oracle VM VirtualBox [Product ID 8370]
  • Oracle Warehouse Builder [Product ID 9]
  • Oracle WebCenter Content [Product ID 2271]
  • Oracle WebCenter Content: Imaging [Product ID 4576]
  • Oracle WebCenter Enterprise Capture [Product ID 10212]
  • Oracle WebLogic Server (not exploitable) [Product ID 5242] [See MOS Note 2827793.1]
  • Oracle ZFS Storage Appliance Kit [Product ID 10026]
  • PeopleSoft Enterprise CRM Client Management [Product ID 4860]
  • PeopleSoft Enterprise CS Install [Product ID 9068]
  • PeopleSoft Enterprise FIN Install [Product ID 8925]
  • PeopleSoft Enterprise FIN Supply Chain Portal Pack Brazil [Product ID 8883]
  • PeopleSoft Enterprise HCM Human Resources [Product ID 5071]
  • PeopleSoft Enterprise PRTL Interaction Hub [Product ID 5090]
  • Policy Automation for Mobile Devices [Product ID 5626]
  • Portable ClusterWare [Product ID 5]
  • Private Cloud Appliance [Product ID 10635]
  • Rapid Planning [Product ID 5235]
  • Secure Global Desktop [Product ID 8539]
  • Siebel Core - Services Security [Product ID 9001]
  • Sun StorageTek Tape Library ACSLS [Product ID 10088]
  • Tekelec Platform [Product ID 11269]
  • Transportation Management [Product ID 1991]
  • Universal Installer [Product ID 662]
  • Zero Data Loss Recovery Appliance [Product ID 11342]

Reference (need to login):

https://support.oracle.com/epmos/faces/DocumentDisplay?_afrLoop=294496371045198&id=2827611.1&_afrWindowMode=0&_adf.ctrl-state=aof21bja3_4

That Oracle note says that patching the Oracle Client isn't needed:

5.0 Oracle products not requiring patches:
Oracle Client [Product ID 5]

However I see Log4j files in the Oracle Client 12.2 installation:

..\product\12.2.0\client_1\sqldeveloper\sqldeveloper\lib\log4j-1.2.13.jar

I'm a little bit confused...

It looks like it uses Log4j version 1.2, which is not affected by the current vulnerability of Log4j. That's why it is listed as no patches required.

Related