Security vulnerability scanners may report vulnerable versions of Apache log4j libraries within the CA Service Management installation directory after patching. These files typically reside in the REPLACED or temp folder structures. This article describes the risk profile of these files and the recommended procedure for their removal or mitigation.
Vulnerability scanners report log4j-core-2.10.0.jar or log4j-core-2.12.0.jar as vulnerable (requiring 2.12.2 or higher) in the following example paths:
NX_ROOT\REPLACED\HYD-761_CUM_C.OLD\bopcfg\www\CATALINA_BASE\webapps\AMS.warNX_ROOT\REPLACED\hyd-761_tool.OLD\java\lib\log4j-core-2.12.0.jarNX_ROOT\temp\hyd-368_cum_C\log4j-core-2.12.0.jarFiles in the REPLACED folder structure are backups created automatically during patch installation or upgrades. Files in the temp folder are artifacts from the installation process. These files are not included in the active executable library path and do not pose an active runtime security risk; however, they remain detectable by file-system scanners.
To address scanner alarms, follow these steps to manage the backup and temporary files:
NX_ROOT\temp directory. These files are artifacts and are no longer required for system operation.REPLACED folder, zip the contents and move the archive to a location outside of the application's installation path, or delete the files entirely.NX_ROOT\REPLACED\Visualizer.OLD directory (or any REPLACED folder pertaining to Service Desk Visualizer). Removal of these specific directories may prevent successful future upgrades.For further details regarding the Visualizer upgrade scenario, see .