CodeMeter protected application error "JVMTI" when using Cortex XDR

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements

Content translations are temporarily unavailable due to site maintenance. We apologize for any inconvenience. Visit our blog to learn more.

CodeMeter protected application error "JVMTI" when using Cortex XDR

L0 Member

The Java Application i am developing is using WIBU CodeMeter Software to prevent Hacker attacks.

CodeMeter from Wibu-Systems: Secure protection & license management of software and digital content:...

 

Currently we protect the application, so that no one can establish a Debug Connection with the JavaVM to be able to read/change values hold in memory.

 

CodeMeter is using the JVMTI interface for blocking these kind of attacks.

 

We have released an application 3 years ago and it always worked, but since 2 weeks the same application can not be started anymore, after Cortex XDR was updated.

It seems that the Cortex XDR Virus Scanner is also trying to use the JVMTI interface and because 2 application trying to "manipulate" my application the application breaks.

 

 

  1. Do you now an option/configuration/module which i can de-activate in CortexXDR to prevent the JVMTI usage?
  2. Is there something like an "Injection-Module" which can be de-activated for java.exe applications?

 

 

1 accepted solution

Accepted Solutions

L3 Networker

Hi MarkusL,

Yes, for this you will need to navigate to your Exploit Protection Profiles and under the "Known Vulnerable Processes Protection" module you will see "Java Deserialization Protection" with a default setting of "Enabled". By disabling that specific protection for the effected hosts I believe your issue will be resolved.

View solution in original post

1 REPLY 1

L3 Networker

Hi MarkusL,

Yes, for this you will need to navigate to your Exploit Protection Profiles and under the "Known Vulnerable Processes Protection" module you will see "Java Deserialization Protection" with a default setting of "Enabled". By disabling that specific protection for the effected hosts I believe your issue will be resolved.

  • 1 accepted solution
  • 3596 Views
  • 1 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!