PT-2020-20743 · Oracle+1 · Java Rmi Server+1

Published

2020-03-04

·

Updated

2021-07-21

·

CVE-2020-9761

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions UNCTAD ASYCUDA World versions 2001 through 2020
Description The Java RMI Server in UNCTAD ASYCUDA World has an insecure default configuration. This leads to Java code execution from a remote URL because an RMI Distributed Garbage Collector method is called.
Recommendations For versions 2001 through 2020, consider reconfiguring the Java RMI Server to secure its default settings, focusing on proper configuration of the RMI Distributed Garbage Collector method to prevent remote code execution. As a temporary workaround, restrict access to the Java RMI Server until a secure configuration can be implemented.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2020-9761

Affected Products

Java Rmi Server
Unctad Asycuda World