<?xml version="1.0" encoding="UTF-8" ?>
<?xml-stylesheet type="text/xsl" href="https://community.appian.com/cfs-file/__key/system/syndication/rss.xsl" media="screen"?><rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/"><channel><title>KB-1970 Port 1099 network security vulnerability</title><link>https://community.appian.com/support/w/kb/1495/kb-1970-port-1099-network-security-vulnerability</link><description /><dc:language>en-US</dc:language><generator>Telligent Community 12</generator><item><title>KB-1970 Port 1099 network security vulnerability</title><link>https://community.appian.com/support/w/kb/1495/kb-1970-port-1099-network-security-vulnerability</link><pubDate>Wed, 24 Jan 2024 22:59:56 GMT</pubDate><guid isPermaLink="false">d3a83456-d57b-489c-a84c-4e8267bb592a:2def7616-82b6-4d97-bc4a-d163058a0baa</guid><dc:creator>pauline.delacruz</dc:creator><comments>https://community.appian.com/support/w/kb/1495/kb-1970-port-1099-network-security-vulnerability#comments</comments><description>Current Revision posted to Appian Knowledge Base by pauline.delacruz on 1/24/2024 10:59:56 PM&lt;br /&gt;
&lt;h2&gt;Symptoms&lt;/h2&gt;
&lt;p&gt;Following a network vulnerability/security scan, reports indicate a violation on port 1099. The scan shows a&amp;nbsp;remote Java JMX agent is configured without SSL client and password authentication.&lt;/p&gt;
&lt;h2&gt;Cause&lt;/h2&gt;
&lt;p&gt;The process listening on port 1099 is started by ActiveMQ to run the JMS broker. This process is started by default when Tomcat is started and exposes a JMX listener for monitoring/administration on port 1099 at startup.&lt;/p&gt;
&lt;h2&gt;Action&lt;/h2&gt;
&lt;ol&gt;
&lt;li&gt;Shut down the application server.&lt;/li&gt;
&lt;li&gt;Add the following line to&amp;nbsp;&lt;strong&gt;custom.properties&lt;/strong&gt; file in &lt;code&gt;&lt;tt&gt;&amp;lt;APPIAN_HOME&amp;gt;/conf:&lt;/tt&gt;&lt;/code&gt;
&lt;pre class="code panel"&gt;conf.jms.embeddedBrokerUrl=broker:(tcp:&lt;span class="code-comment"&gt;//0.0.0.0:61616)?useJmx=&lt;span class="code-keyword"&gt;false&lt;/span&gt;&lt;/span&gt;&lt;/pre&gt;
&lt;/li&gt;
&lt;li&gt;Start the application server.&lt;/li&gt;
&lt;/ol&gt;
&lt;h2&gt;Affected Versions&lt;/h2&gt;
&lt;p&gt;This article applies to all versions earlier than 20.4 which use Tomcat as an application server.&lt;/p&gt;
&lt;p&gt;Last Reviewed: January 2024&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;

&lt;div style="font-size: 90%;"&gt;Tags: Tomcat, Security, application server, infrastructure, network&lt;/div&gt;
</description></item><item><title>KB-1970 Port 1099 network security vulnerability</title><link>https://community.appian.com/support/w/kb/1495/kb-1970-port-1099-network-security-vulnerability/revision/4</link><pubDate>Thu, 25 Jul 2019 00:33:48 GMT</pubDate><guid isPermaLink="false">d3a83456-d57b-489c-a84c-4e8267bb592a:2def7616-82b6-4d97-bc4a-d163058a0baa</guid><dc:creator>Parmida Borhani</dc:creator><comments>https://community.appian.com/support/w/kb/1495/kb-1970-port-1099-network-security-vulnerability#comments</comments><description>Revision 4 posted to Appian Knowledge Base by Parmida Borhani on 7/25/2019 12:33:48 AM&lt;br /&gt;
&lt;h2&gt;Symptoms&lt;/h2&gt;
&lt;p&gt;Following a network vulnerability/security scan, reports indicate a violation on port 1099. The scan shows a&amp;nbsp;remote Java JMX agent is configured without SSL client and password authentication.&lt;/p&gt;
&lt;h2&gt;Cause&lt;/h2&gt;
&lt;p&gt;The process listening on port 1099 is started by ActiveMQ to run the JMS broker. This process is started by default when Tomcat is started and exposes a JMX listener for monitoring/administration on port 1099 at startup.&lt;/p&gt;
&lt;h2&gt;Action&lt;/h2&gt;
&lt;ol&gt;
&lt;li&gt;Shut down the application server.&lt;/li&gt;
&lt;li&gt;Add the following line to&amp;nbsp;&lt;strong&gt;custom.properties&lt;/strong&gt; file in &lt;code&gt;&lt;tt&gt;&amp;lt;APPIAN_HOME&amp;gt;/conf:&lt;/tt&gt;&lt;/code&gt;
&lt;pre class="code panel"&gt;conf.jms.embeddedBrokerUrl=broker:(tcp:&lt;span class="code-comment"&gt;//0.0.0.0:61616)?useJmx=&lt;span class="code-keyword"&gt;false&lt;/span&gt;&lt;/span&gt;&lt;/pre&gt;
&lt;/li&gt;
&lt;li&gt;Start the application server.&lt;/li&gt;
&lt;/ol&gt;
&lt;h2&gt;Affected Versions&lt;/h2&gt;
&lt;p&gt;This article applies to all versions of Appian using Tomcat as an application server.&lt;/p&gt;
&lt;p&gt;Last Reviewed: July 2019&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;

&lt;div style="font-size: 90%;"&gt;Tags: Tomcat, Security, application server, infrastructure, network&lt;/div&gt;
</description></item><item><title>DRAFT KB-XXXX Port 1099 network security vulnerability</title><link>https://community.appian.com/support/w/kb/1495/kb-1970-port-1099-network-security-vulnerability/revision/3</link><pubDate>Wed, 24 Jul 2019 14:43:53 GMT</pubDate><guid isPermaLink="false">d3a83456-d57b-489c-a84c-4e8267bb592a:2def7616-82b6-4d97-bc4a-d163058a0baa</guid><dc:creator>James Lee</dc:creator><comments>https://community.appian.com/support/w/kb/1495/kb-1970-port-1099-network-security-vulnerability#comments</comments><description>Revision 3 posted to Appian Knowledge Base by James Lee on 7/24/2019 2:43:53 PM&lt;br /&gt;
&lt;h2&gt;Symptoms&lt;/h2&gt;
&lt;p&gt;Following a network vulnerability/security scan, reports indicate a violation on port 1099. The scan shows a&amp;nbsp;remote Java JMX agent is configured without SSL client and password authentication.&lt;/p&gt;
&lt;h2&gt;Cause&lt;/h2&gt;
&lt;p&gt;The process listening on port 1099 is started by ActiveMQ to run the JMS broker. This process is started by default when Tomcat is started and exposes a JMX listener for monitoring/administration on port 1099 at startup.&lt;/p&gt;
&lt;h2&gt;Action&lt;/h2&gt;
&lt;ol&gt;
&lt;li&gt;Shut down the application server.&lt;/li&gt;
&lt;li&gt;Add the following line to&amp;nbsp;&lt;strong&gt;custom.properties&lt;/strong&gt; file in &lt;code&gt;&lt;tt&gt;&amp;lt;APPIAN_HOME&amp;gt;/conf:&lt;/tt&gt;&lt;/code&gt;
&lt;pre class="code panel"&gt;conf.jms.embeddedBrokerUrl=broker:(tcp:&lt;span class="code-comment"&gt;//0.0.0.0:61616)?useJmx=&lt;span class="code-keyword"&gt;false&lt;/span&gt;&lt;/span&gt;&lt;/pre&gt;
&lt;/li&gt;
&lt;li&gt;Start the application server.&lt;/li&gt;
&lt;/ol&gt;
&lt;h2&gt;Affected Versions&lt;/h2&gt;
&lt;p&gt;This article applies to all versions of Appian using Tomcat as an application server.&lt;/p&gt;
&lt;p&gt;Last Reviewed: July 2019&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;

&lt;div style="font-size: 90%;"&gt;Tags: Tomcat, Security, application server, infrastructure, network&lt;/div&gt;
</description></item><item><title>DRAFT KB-XXXX Port 1099 network security vulnerability</title><link>https://community.appian.com/support/w/kb/1495/kb-1970-port-1099-network-security-vulnerability/revision/2</link><pubDate>Tue, 23 Jul 2019 21:54:30 GMT</pubDate><guid isPermaLink="false">d3a83456-d57b-489c-a84c-4e8267bb592a:2def7616-82b6-4d97-bc4a-d163058a0baa</guid><dc:creator>James Lee</dc:creator><comments>https://community.appian.com/support/w/kb/1495/kb-1970-port-1099-network-security-vulnerability#comments</comments><description>Revision 2 posted to Appian Knowledge Base by James Lee on 7/23/2019 9:54:30 PM&lt;br /&gt;
&lt;h2&gt;Symptoms&lt;/h2&gt;
&lt;p&gt;Following a network vulnerability/security scan, reports indicate a violation on port 1099. The scan shows a&amp;nbsp;remote Java JMX agent is configured without SSL client and password authentication.&lt;/p&gt;
&lt;h2&gt;Cause&lt;/h2&gt;
&lt;p&gt;The process listening on port 1099 is started by ActiveMQ to run the JMS broker. This process is started by default when Tomcat is started and exposes a JMX listener for monitoring/administration on port 1099 at startup.&lt;/p&gt;
&lt;h2&gt;Action&lt;/h2&gt;
&lt;ol&gt;
&lt;li&gt;Shut down the application server.&lt;/li&gt;
&lt;li&gt;Add the following lines to&amp;nbsp;&lt;strong&gt;custom.properties&lt;/strong&gt; file in &lt;tt&gt;&amp;lt;APPIAN_HOME&amp;gt;/conf:&lt;/tt&gt;
&lt;pre class="code panel"&gt;conf.jms.embeddedBrokerUrl=broker:(tcp:&lt;span class="code-comment"&gt;//0.0.0.0:61616)?useJmx=&lt;span class="code-keyword"&gt;false&lt;/span&gt;&lt;/span&gt;&lt;/pre&gt;
&lt;/li&gt;
&lt;li&gt;Restart the application server.&lt;/li&gt;
&lt;/ol&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;h2&gt;Affected Versions&lt;/h2&gt;
&lt;p&gt;This article applies to all versions of Appian using Tomcat as an application server.&lt;/p&gt;
&lt;p&gt;Last Reviewed: July 2019&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;

&lt;div style="font-size: 90%;"&gt;Tags: Security, application server, infrastructure&lt;/div&gt;
</description></item><item><title>DRAFT KB-XXXX Port 1099 network security vulnerability</title><link>https://community.appian.com/support/w/kb/1495/kb-1970-port-1099-network-security-vulnerability/revision/1</link><pubDate>Tue, 23 Jul 2019 21:12:34 GMT</pubDate><guid isPermaLink="false">d3a83456-d57b-489c-a84c-4e8267bb592a:2def7616-82b6-4d97-bc4a-d163058a0baa</guid><dc:creator>James Lee</dc:creator><comments>https://community.appian.com/support/w/kb/1495/kb-1970-port-1099-network-security-vulnerability#comments</comments><description>Revision 1 posted to Appian Knowledge Base by James Lee on 7/23/2019 9:12:34 PM&lt;br /&gt;
&lt;h2&gt;Symptoms&lt;/h2&gt;
&lt;p&gt;Following a network vulnerability/security scan, reports indicate a violation on port 1099. Scan shows a&amp;nbsp;remote Java JMX agent is configured without SSL client and password authentication.&lt;/p&gt;
&lt;h2&gt;Cause&lt;/h2&gt;
&lt;p&gt;The process listening on port 1099 is started by ActiveMQ to run the JMS broker. This process is started by default when we start Tomcat, and exposes a JMX listener for monitoring/administration on port 1099 at startup.&lt;/p&gt;
&lt;h2&gt;Action&lt;/h2&gt;
&lt;ol&gt;
&lt;li&gt;Shut down the Appian application server.&lt;/li&gt;
&lt;li&gt;Open the &lt;strong&gt;custom.properties&lt;/strong&gt; file in &lt;tt&gt;&amp;lt;APPIAN_HOME&amp;gt;/conf&lt;/tt&gt;&lt;/li&gt;
&lt;li&gt;Add the following line:
&lt;pre class="code panel"&gt;conf.jms.embeddedBrokerUrl=broker:(tcp:&lt;span class="code-comment"&gt;//0.0.0.0:61616)?useJmx=&lt;span class="code-keyword"&gt;false&lt;/span&gt;&lt;/span&gt;&lt;/pre&gt;
&lt;/li&gt;
&lt;li&gt;Restart the application server.&lt;/li&gt;
&lt;/ol&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;h2&gt;Affected Versions&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;This article applies to all versions of Appian using tomcat as an application server.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Last Reviewed: Month YYYY&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;

&lt;div style="font-size: 90%;"&gt;Tags: Security, application server, infrastructure&lt;/div&gt;
</description></item></channel></rss>