Apache log4j vulnerability detected in REPLACED and temp folders - CA Service Management
search cancel

Apache log4j vulnerability detected in REPLACED and temp folders - CA Service Management

book

Article ID: 231849

calendar_today

Updated On:

Products

CA Service Management - Service Desk Manager CA Service Desk Manager

Issue/Introduction

Security vulnerability scanners may report vulnerable versions of Apache log4j libraries within the CA Service Management installation directory after patching. These files typically reside in the REPLACED or temp folder structures. This article describes the risk profile of these files and the recommended procedure for their removal or mitigation.

Vulnerability scanners report log4j-core-2.10.0.jar or log4j-core-2.12.0.jar as vulnerable (requiring 2.12.2 or higher) in the following example paths:

  • NX_ROOT\REPLACED\HYD-761_CUM_C.OLD\bopcfg\www\CATALINA_BASE\webapps\AMS.war
  • NX_ROOT\REPLACED\hyd-761_tool.OLD\java\lib\log4j-core-2.12.0.jar
  • NX_ROOT\temp\hyd-368_cum_C\log4j-core-2.12.0.jar

Environment

  • Release: 17.3 and higher
  • Component: CA Service Management (Service Desk Manager)
  • Operating System: Windows, Linux

Cause

Files in the REPLACED folder structure are backups created automatically during patch installation or upgrades. Files in the temp folder are artifacts from the installation process. These files are not included in the active executable library path and do not pose an active runtime security risk; however, they remain detectable by file-system scanners.

Resolution

To address scanner alarms, follow these steps to manage the backup and temporary files:

  1. Identify the location of the reported vulnerable files.
  2. Delete all files within the NX_ROOT\temp directory. These files are artifacts and are no longer required for system operation.
  3. For files in the REPLACED folder, zip the contents and move the archive to a location outside of the application's installation path, or delete the files entirely.
  4. CRITICAL: Do not delete the NX_ROOT\REPLACED\Visualizer.OLD directory (or any REPLACED folder pertaining to Service Desk Visualizer). Removal of these specific directories may prevent successful future upgrades.

For further details regarding the Visualizer upgrade scenario, see Service Desk Manager Rollup (RU) patch install or upgrade error (KB 235698).

Additional Information