Remote Code Execution Risk in Apache JMeter Server by Apache
CVE-2018-1287
9.8CRITICAL
Summary
Apache JMeter versions 2.X and 3.X have a security vulnerability when configured for distributed testing using RMI. The issue arises from the jmeter server binding the RMI Registry to a wildcard host, potentially allowing unauthorized attackers to access the JMeter Engine and execute malicious code. This exposure highlights the importance of secure configuration practices to prevent unauthorized access in distributed testing environments.
Affected Version(s)
Apache JMeter 2.x
Apache JMeter 3.x
References
CVSS V3.1
Score:
9.8
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved