How to disable the JMX network port (for CVE-2023-22508)

Still need help?

The Atlassian Community is here for you.

Ask the community


Platform notice: Server and Data Center only. This article only applies to Atlassian products on the Server and Data Center platforms.

Support for Server* products ended on February 15th 2024. If you are running a Server product, you can visit the Atlassian Server end of support announcement to review your migration options.

*Except Fisheye and Crucible

Summary

If you're running a Confluence Server or Data Center instance then you may have been reading about CVE-2023-22508:

CONFSERVER-88221 - Getting issue details... STATUS

If you're running an affected version of Confluence, you're only vulnerable if you currently have a TCP port enabled for JMX, as outlined in Live Monitoring Using the JMX Interface.     TCP ports for JMX are not configured by default in Confluence.


On Windows:

JMX parameters will either be in setenv.bat within your <installation_path>/bin/  directory (if you start Confluence from the .bat file) or in the Java tab of your Windows service - see Configuring System Properties for more information.

set CATALINA_OPTS=-Dcom.sun.management.jmxremote %CATALINA_OPTS%
set CATALINA_OPTS=-Dcom.sun.management.jmxremote.port=8099 %CATALINA_OPTS%

On Linux:

JMX parameters will be listed in the setenv.sh file within your <installation_path>/bin/ directory:

CATALINA_OPTS="-Dcom.sun.management.jmxremote ${CATALINA_OPTS}"
CATALINA_OPTS="-Dcom.sun.management.jmxremote.port=8099 ${CATALINA_OPTS}"


Environment

Check your version of Confluence by expanding the macro below.

Click here to check your Confluence version...

Even if your Confluence version is impacted, you must have also configured a JMX network port (as above) to be vulnerable.    If you have never configured remote JMX monitoring, you are not vulnerable, even if your version contains the vulnerability.

For Confluence 8.x, this is fixed in 8.2 and later versions.

For Confluence 7.19.x (LTS), this is fixed in 7.19.8.

For Confluence 7.13.x (LTS), this is fixed in 7.13.20.

VersionImpact
8.4(tick) Not vulnerable
8.3.2(tick) Not vulnerable
8.3.1(tick) Not vulnerable
8.3(tick) Not vulnerable
8.2.3(tick) Not vulnerable
8.2.2(tick) Not vulnerable
8.2.1(tick) Not vulnerable
8.2(tick) Not vulnerable
8.1.4(error) Impacted if a JMX port is configured
8.1.3(error) Impacted if a JMX port is configured
8.1.2(error) Impacted if a JMX port is configured
8.1.1(error) Impacted if a JMX port is configured
8.1(error) Impacted if a JMX port is configured
8.0.4(error) Impacted if a JMX port is configured
8.0.3(error) Impacted if a JMX port is configured
8.0.2(error) Impacted if a JMX port is configured
8.0.1(error) Impacted if a JMX port is configured
8.0(error) Impacted if a JMX port is configured
7.20.3(error) Impacted if a JMX port is configured
7.20.2(error) Impacted if a JMX port is configured
7.20.1(error) Impacted if a JMX port is configured
7.20(error) Impacted if a JMX port is configured
7.19.11(tick) Not vulnerable
7.19.10(tick) Not vulnerable
7.19.9(tick) Not vulnerable
7.19.8(tick) Not vulnerable
7.19.7(error) Impacted if a JMX port is configured
7.19.6(error) Impacted if a JMX port is configured
7.19.5(error) Impacted if a JMX port is configured
7.19.4(error) Impacted if a JMX port is configured
7.19.3(error) Impacted if a JMX port is configured
7.19.2(error) Impacted if a JMX port is configured
7.19.1(error) Impacted if a JMX port is configured
7.19(error) Impacted if a JMX port is configured
7.18.3(error) Impacted if a JMX port is configured
7.18.2(error) Impacted if a JMX port is configured
7.18.1(error) Impacted if a JMX port is configured
7.18(error) Impacted if a JMX port is configured
7.17.5(error) Impacted if a JMX port is configured
7.17.4(error) Impacted if a JMX port is configured
7.17.3(error) Impacted if a JMX port is configured
7.17.2(error) Impacted if a JMX port is configured
7.17.1(error) Impacted if a JMX port is configured
7.17(error) Impacted if a JMX port is configured
7.16.5(error) Impacted if a JMX port is configured
7.16.4(error) Impacted if a JMX port is configured
7.16.3(error) Impacted if a JMX port is configured
7.16.2(error) Impacted if a JMX port is configured
7.16.1(error) Impacted if a JMX port is configured
7.16(error) Impacted if a JMX port is configured
7.15.3(error) Impacted if a JMX port is configured

7.15.2

(error) Impacted if a JMX port is configured
7.15.1(error) Impacted if a JMX port is configured
7.15(error) Impacted if a JMX port is configured
7.14.4(error) Impacted if a JMX port is configured
7.14.3(error) Impacted if a JMX port is configured
7.14.2(error) Impacted if a JMX port is configured
7.14.1(error) Impacted if a JMX port is configured
7.14(error) Impacted if a JMX port is configured
7.13.20(tick) Not vulnerable
7.13.19(error) Impacted if a JMX port is configured
7.13.18(error) Impacted if a JMX port is configured
7.13.17(error) Impacted if a JMX port is configured
7.13.16(error) Impacted if a JMX port is configured
7.13.15(error) Impacted if a JMX port is configured
7.13.14(error) Impacted if a JMX port is configured
7.13.13(error) Impacted if a JMX port is configured
7.13.12(error) Impacted if a JMX port is configured
7.13.11(error) Impacted if a JMX port is configured
7.13.10(error) Impacted if a JMX port is configured
7.13.9(error) Impacted if a JMX port is configured
7.13.8(error) Impacted if a JMX port is configured
7.13.7(error) Impacted if a JMX port is configured
7.13.6(error) Impacted if a JMX port is configured
7.13.5(error) Impacted if a JMX port is configured
7.13.4(error) Impacted if a JMX port is configured
7.13.3(error) Impacted if a JMX port is configured
7.13.2(error) Impacted if a JMX port is configured
7.13.1(error) Impacted if a JMX port is configured
7.13(error) Impacted if a JMX port is configured
7.12.x and below(error) Impacted if a JMX port is configured


Solution

If you haven't enabled the com.sun.management.jmx* JVM parameters as outlined above, your Confluence instance is not vulnerable to CVE-2023-22508, even if you're on an affected version.

However, if you have configured JMX on a TCP port and wish to shut it down, you can remove the com.sun.management.jmx*  parameters from your Confluence JVM parameter list (as shown in the code blocks above) and then restart Confluence.   

Example

Before removal, I may have had JMX configured on port 8099 (for example) using one of the above code blocks in my Confluence JVM parameters.  This would show as LISTEN in netstat  output:

$ netstat -an | grep LISTEN
tcp46      0      0  *.5801                 *.*                    LISTEN     
tcp46      0      0  *.8090                 *.*                    LISTEN     
tcp46      0      0  *.60770                *.*                    LISTEN     
tcp46      0      0  *.8099                 *.*                    LISTEN        <<----  Example JMX port (actual port number depends on JVM parameter used)

Once JMX parameters have been removed and Confluence restarted, you should observe that the JMX port is no longer LISTENING via a netstat  command.

$ netstat -an | grep 8099
$ 


If you have any questions then Atlassian recommends that you open a support ticket for further advice and assistance.  When opening a support ticket, you will receive a quicker answer if you're able to generate and attach a support zip.


Last modified on Jul 28, 2023

Was this helpful?

Yes
No
Provide feedback about this article
Powered by Confluence and Scroll Viewport.