2

The security team has reported some vulnerability "Java Debug Wire Protocol Remote Code Execution Vulnerability" and asked to disable it

I know that we can run the java instance with the jdwp parameters and we are using this in the BPM suite that we are using.

-Xrunjdwp:transport=dt_socket,server=y,address=8888,suspend=n

I can remove it from there. But anyone who is using that suite can enable it again

Is there any way to disable it globally(At server level) so that no one can create a java instance with jdwp enabled

Andromeda
  • 12,659
  • 20
  • 77
  • 103

0 Answers0