Forum Discussion

nbu2020's avatar
nbu2020
Level 2
5 years ago

Netbackup web management console Tomcat

Hi,

Is it possible to launch Java GUI even without the /usr/openv/wmc directory. This directory contains tom cat server files which are being flagged for vulnerabilities.

 

So can i remove the above directory and still have a operational JAVA GUI ?

 

Thanks.

  • nbu2020's avatar
    nbu2020
    5 years ago

    update:

    Thanks for the feedback here. I tested removing the /usr/openv/wmc directory, and restarted netbackup server. I was able to relaunch the java admin console w/o issues.

     

  • I wouldn't recommand to do this.. but it depeneds on your needs actually.. is the nbu version 7.6 as tagged in your post?

    have you tried to open the Console after that change? (you can move it to another path and try, and if it doesn't work.. do a roll back..)

    which vulnerabilites that you get?

     

    • nbu2020's avatar
      nbu2020
      Level 2

       Thanks for your response. Basically the Tomcat install in  the NB setup is getting flagged, even though we dont use any web gui.

       

      Here is the main link of the vulnerabilities being reported for TomCat-

      https://www.tenable.com/plugins/nessus/77475

       

      And no we have not removed it yet. So wanted to check here and see if anyone sees any issues before we remove the files. Yes plan is to put them back if it breaks the Java GUI.

      • davidmoline's avatar
        davidmoline
        Level 6

        If you really are at NBU version 7.6, then you can probably do without the tomcat files (to be fair, I have not tested this, nor do I recommend this). And if you are at version 7.6, then you should really think about upgrading to a supported version - you will probably find that the tomcat vulnerabilities also go away.

        If you are at a modern NetBackup version, then the tomcat server is not just for a web UI, it is also used to distribute security ceritifcates and other vitally important NBU stuff - removing it will break NetBackup.

  • also if it is 7.6 this utility is used for Symantec NetBackup™ Plug-in for VMware vSphere Web Client Guide.. as waell as all other web services.. as described in https://sort.veritas.com/DocPortal/pdf/ka6j0000000BPF0AAO

     

    "By default, the NetBackup Web Services are disabled on the master server. To
    allow the NetBackup plug-in for vSphere Web Client to communicate with the master
    server, the NetBackup administrator must enable the NetBackup Web Services."

    I you can't find access to that link please let me know :)

    hope I could give you a little help regarding this