Security Scanners Are Still Detecting CVE-2022-23302 Vulnerability in the AM Server Even After Upgrading to v8.6 Patch 3
2 years ago
Article Number
000069048
Applies To
RSA Product Set: RSA SecurID
RSA Product/Service Type: Authentication Manager
RSA Version/Condition: 8.6 Patch 3
Issue
After upgrading the Authentication Manager to v8.6 P3, security scanners are still detecting CVE-2022-23302 vulnerability. 
 
/opt/rsa/am/appserver/wls/.patch_storage/34236279_Jun_2_2022_21_32_46/files/oracle.wls.core.app.server/12.2.1.4.0/wls.common.symbol/modules/oracle.owasp/com-bea-core-apache-log4j.jar Installed version : 1.2.17
/opt/rsa/am/appserver/wls/.patch_storage/34236279_Jun_2_2022_21_32_46/files/oracle.wls.libraries/12.2.1.4.0/wls.common.symbol/modules/com.bea.core.apache.log4j.jar Installed version : 1.2.17

 
Cause
Oracle saves backup copies of replaced/patched files under the ".patch_storage" directory. 
 
Resolution
Remove any files located in the ".patch_storage" directory. This will not have any impact on the RSA Authentication Manager since that those are only backups of previous versions and are not actively utilized by the server.