Your IT department is stating that Automation Engine is using Tomcat JBoss v4. They have determined that this version is a security risk.
Answer
The JBoss cannot be upgraded.
First of all, the webserver in the Automation Engine appserver is running on port 8080, this port is protected and should be protected by the firewall protecting the intranet from the customer, so the JMX and WS services mentioned can only be accessed on the intranet, not from the internet.
If you want to protect your installation against internal attacks, you can completely remove the JMX and WS services since they are normally not used in production.
Version 12
To do so, remove the following files from your appserver installation:
Automation Engine 14.1 and newer modified the contents of this folder, so this KB only applies to Automation Engine 14.0 and older. See later KB by searching for JMX Security.
2 Comments
Anonymous
"normally not used"
When are they used?
What is the risk of removing them?
Anonymous
Bump