PT-2020-20743 · Oracle+1 · Java Rmi Server+1
Published
2020-03-04
·
Updated
2021-07-21
·
CVE-2020-9761
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
UNCTAD ASYCUDA World versions 2001 through 2020
Description
The Java RMI Server in UNCTAD ASYCUDA World has an insecure default configuration. This leads to Java code execution from a remote URL because an RMI Distributed Garbage Collector method is called.
Recommendations
For versions 2001 through 2020, consider reconfiguring the Java RMI Server to secure its default settings, focusing on proper configuration of the RMI Distributed Garbage Collector method to prevent remote code execution. As a temporary workaround, restrict access to the Java RMI Server until a secure configuration can be implemented.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Java Rmi Server
Unctad Asycuda World