Is it possible to eliminate log4j.jar from the directory /usr/share/java on Rhel7/Tomcat7, as part of the process of removing Log4J vulnerability?

asked 2023-05-22 03:17:58 +0000

nofretete gravatar image

answered 2023-05-22 03:33:01 +0000

lalupa gravatar image

No, it is not recommended to eliminate log4j.jar from the directory /usr/share/java on Rhel7/Tomcat7 because log4j might be required for the proper functioning of your applications. Instead, it is recommended to upgrade to the latest version of log4j, which fixes the vulnerability or apply the suggested mitigation measures until the patch is available.

Asked: 2023-05-22 03:17:58 +0000

Last updated: May 22 '23