Multiple entitlements in RSA Identity Governance and Lifecycle cause supervisor approval to fail with ORA-22275: invalid LOB locator specified
Originally Published: 2017-09-18
Article Number
Applies To
RSA Version/Condition: 7.x
Issue
After requesting multiple entitlements in RSA Identity Governance & Lifecycle, the request fails during supervisor approval. The error occurs when updating CLOB field VAR_CVALUE in the WP_USER_DATA table if the data is greater than 2000 characters in length. Conceivably, this error may also arise in other parts of the product.
- The error message in the processing workflow is An SQL Exception has occurred. Please see the server logs for details.
- The error message in the WorkPoint.log is:
2017-08-23 11:55:10,649 [Worker_alertq#Alert Queue#WPDS_1] ERROR com.workpoint.services.impl.GenericServiceImpl - ORA-22275: invalid LOB locator specified SQL = Execute Batch: UPDATE WP_USER_DATA SET VAR_CVALUE=?, VAR_BVALUE=?, BVALUE_LENGTH=?, PROC_ID=?, PROC_DB=?, PROCI_ID=?, PROCI_DB=?, ROW_VERSION=?, LU_ID=?, LU_DATE=? WHERE DATA_ID=? AND DATA_DB=? AND DATA_TYPE=? AND VAR_NAME=?
- The error is NOT seen in the aveksaServer.log.
Cause
The issue can affect all 7.x versions, as that is when RSA Identity Governance & Lifecycle switched to using a 12.2.0.1 Oracle database.
Resolution
RSA-supplied database users such as Appliance users should install and run the latest available RSA Identity Governance & Lifecycle Appliance Updater which contains cumulative Oracle patches.
Customer-supplied database users should install the latest PSU (Oracle Patch Set Update).
Related Articles
RSA-2025-04: RSA Governance and Lifecycle Security Update for Oracle Database Vulnerabilities 36Number of Views Access Fulfillment Express (AFX) Workflow does not automatically execute when there is no approval phase in RSA Identity G… 12Number of Views RSA Identity Governance and Lifecycle 7.2.1 Patch 08 Release Notes 23Number of Views RSA Governance & Lifecycle Integration: RSA SecurID Access - Authentication Manager 48Number of Views Revoked local entitlements are auto-completed by the system after collections are run in RSA Identity Governance & Lifecycle 67Number of Views
Trending Articles
Download RSA SecurID Access Cloud User Event audit logs using Cloud Administration REST API CLU RSA Authentication Manager 8.9 Release Notes (January 2026) AFX Server Fails to Start with 'Could Not Build a Validated Path' and 'Timed Out Waiting for AFX Applications to Start' in… AFX Server stuck in 'Not running' State, with error 'timed out waiting for AFX applications to start' Quick Setup Guide - Passwordless Authentication in Windows MFA Agent for Active Directory
Don't see what you're looking for?