Vulnerability scanners report persistent Log4j vulnerabilities in the Oracle 19c home directory. The following files are specifically flagged:
$ORACLE_HOME/suptools/tfa/
$ORACLE_HOME/md/property_graph/
DLP 16.0.1 +
Oracle 19c Standard Edition 2
The flagged libraries belong to the Oracle Property Graph and Trace File Analyzer (TFA) components.
While these are installed as part of the default Oracle 19c SE2 deployment for DLP, they are not used by the DLP.
However, security scanners continue to flag them based on their versioning and presence on the file system.
To remediate these security findings and satisfy compliance requirements, apply the latest Oracle Critical Patch Update (CPU) available via the Broadcom Support Portal. Installing latest patch successfully removes or upgrades the vulnerable Log4j files from both the $ORACLE_HOME/suptools/tfa/ and $ORACLE_HOME/md/property_graph/ directories.
Note: Do not manually delete these files. Removing files from the Oracle home directory can corrupt the inventory and prevent the successful application of future patches.
1. Where can I find the latest Oracle Critical Patch Updates for my DLP install? — Guidance on downloading CPUs from the Broadcom Portal.
2. Download and install Oracle Critical Patch Updates (CPU) for Symantec DLP — Step-by-step instructions for applying Oracle patches.