Remote Code Execution Risk in Apache JMeter Server by Apache
CVE-2018-1287

9.8CRITICAL

Key Information:

Vendor
Apache
Vendor
CVE Published:
14 February 2018

Summary

Apache JMeter versions 2.X and 3.X have a security vulnerability when configured for distributed testing using RMI. The issue arises from the jmeter server binding the RMI Registry to a wildcard host, potentially allowing unauthorized attackers to access the JMeter Engine and execute malicious code. This exposure highlights the importance of secure configuration practices to prevent unauthorized access in distributed testing environments.

Affected Version(s)

Apache JMeter 2.x

Apache JMeter 3.x

References

CVSS V3.1

Score:
9.8
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.