ArcGIS Server 10.3.1: RMIClassLoader RCE

- AV AC AU C I A
发布: 2025-04-13
修订: 2025-04-13

Using an Esri-provided image on Azure's Marketplace, ArcGIS Server 10.3.1 started Java's rmid on port 1098 and explicitly set the property java.rmi.server.useCodebaseOnly equal to false. Screenshot: https://www.dropbox.com/s/xz9ugal3ixnfh1c/10.3.1_rmid_useCodebaseOnly%3Dfalse.png?dl=0 As discussed on Oracle's website, the default value of java.rmi.server.useCodebaseOnly was changed to true in Java 7 Update 21, with a remark that setting it to false could create a risk of RCE. Link: http://docs.oracle.com/javase/7/docs/technotes/guides/rmi/enhancements-7.html While the version of Java included in ArcGIS Server 10.3.1 appears to be Java 7 Update 76, which would have the more secure default setting, that is irrelevant due to the ArcGIS solution manually changing it. Screenshot: https://www.dropbox.com/s/5reh81dwwp9e4dz/10.3.1_rmid_java7u76.png?dl=0 When an attacker can remotely reach rmid on the victim server, and the victim server can reach a web server on a machine controlled by the...

0%
暂无可用Exp或PoC
当前有0条受影响产品信息