CVE-2018-1287
published 2018-02-14CVE-2018-1287: In Apache JMeter 2.X and 3.X, when using Distributed Test only (RMI based), jmeter server binds RMI Registry to wildcard host. This could allow an attacker to…
PriorityP356critical9.8CVSS 3.0
AVNACLPRNUINSUCHIHAH
EPSS
3.42%
87.5th percentile
In Apache JMeter 2.X and 3.X, when using Distributed Test only (RMI based), jmeter server binds RMI Registry to wildcard host. This could allow an attacker to get Access to JMeterEngine and send unauthorized code.
Affected
25 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apache | jmeter | — | — |
| apache | jmeter | — | — |
| apache | jmeter | — | — |
| apache | jmeter | — | — |
| apache | jmeter | — | — |
| apache | jmeter | — | — |
| apache | jmeter | — | — |
| apache | jmeter | — | — |
| apache | jmeter | — | — |
| apache | jmeter | — | — |
| apache | jmeter | — | — |
| apache | jmeter | — | — |
| apache | jmeter | — | — |
| apache | jmeter | — | — |
| apache | jmeter | — | — |
| apache | jmeter | — | — |
| apache | jmeter | — | — |
| apache | jmeter | — | — |
| apache | jmeter | — | — |
| apache | jmeter | — | — |
| apache | jmeter | — | — |
| apache | jmeter | — | — |
| apache_software_foundation | apache_jmeter | — | — |
| apache_software_foundation | apache_jmeter | — | — |
| debian | jakarta-jmeter | — | — |
CVSS provenance
nvdv3.09.8CRITICALCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
osv9.8CRITICAL
vendor_debian9.8LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
Missing certificate validation in Apache JMeter
ghsa·2022-05-13
CVE-2018-1287 [CRITICAL] CWE-347 Missing certificate validation in Apache JMeter
Missing certificate validation in Apache JMeter
In Apache JMeter 2.X and 3.X, when using Distributed Test only (RMI based), jmeter server binds RMI Registry to wildcard host. This could allow an attacker to get Access to JMeterEngine and send unauthorized code. This only affect those running in Distributed mode.
In distributed mode, JMeter makes an architectural assumption that it is operating on a 'safe' network. i.e. everyone with access to the network is considered trusted.
OSV
Missing certificate validation in Apache JMeter
osv·2022-05-13
CVE-2018-1287 [CRITICAL] Missing certificate validation in Apache JMeter
Missing certificate validation in Apache JMeter
In Apache JMeter 2.X and 3.X, when using Distributed Test only (RMI based), jmeter server binds RMI Registry to wildcard host. This could allow an attacker to get Access to JMeterEngine and send unauthorized code. This only affect those running in Distributed mode.
In distributed mode, JMeter makes an architectural assumption that it is operating on a 'safe' network. i.e. everyone with access to the network is considered trusted.
OSV
CVE-2018-1287: In Apache JMeter 2
osv·2018-02-14·CVSS 9.8
CVE-2018-1287 [CRITICAL] CVE-2018-1287: In Apache JMeter 2
In Apache JMeter 2.X and 3.X, when using Distributed Test only (RMI based), jmeter server binds RMI Registry to wildcard host. This could allow an attacker to get Access to JMeterEngine and send unauthorized code.
Debian
CVE-2018-1287: jakarta-jmeter - In Apache JMeter 2.X and 3.X, when using Distributed Test only (RMI based), jmet...
vendor_debian·2018·CVSS 9.8
CVE-2018-1287 [CRITICAL] CVE-2018-1287: jakarta-jmeter - In Apache JMeter 2.X and 3.X, when using Distributed Test only (RMI based), jmet...
In Apache JMeter 2.X and 3.X, when using Distributed Test only (RMI based), jmeter server binds RMI Registry to wildcard host. This could allow an attacker to get Access to JMeterEngine and send unauthorized code.
Scope: local
bookworm: open
bullseye: open
forky: open
sid: open
trixie: open
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://mail-archives.apache.org/mod_mbox/www-announce/201802.mbox/%3CCAH9fUpYsFx1%2Brwz1A%3Dmc7wAgbDHARyj1VrWNg41y9OySuL1mqw%40mail.gmail.com%3Ehttp://www.securityfocus.com/bid/103068https://lists.apache.org/thread.html/31e0adbeca9d865ff74d0906b2248a41a1457cb54c1afbe5947df58b%40%3Cissues.jmeter.apache.org%3Ehttp://mail-archives.apache.org/mod_mbox/www-announce/201802.mbox/%3CCAH9fUpYsFx1%2Brwz1A%3Dmc7wAgbDHARyj1VrWNg41y9OySuL1mqw%40mail.gmail.com%3Ehttp://www.securityfocus.com/bid/103068https://lists.apache.org/thread.html/31e0adbeca9d865ff74d0906b2248a41a1457cb54c1afbe5947df58b%40%3Cissues.jmeter.apache.org%3E
2018-02-14
Published