CVE-2018-1297
published 2018-02-13CVE-2018-1297: When using Distributed Test only (RMI based), Apache JMeter 2.x and 3.x uses an unsecured RMI connection. This could allow an attacker to get Access to…
PriorityP357critical9.8CVSS 3.0
AVNACLPRNUINSUCHIHAH
EPSS
10.10%
95.1th percentile
When using Distributed Test only (RMI based), Apache JMeter 2.x and 3.x uses an unsecured RMI connection. This could allow an attacker to get Access to JMeterEngine and send unauthorized code.
Affected
25 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apache | jmeter | — | — |
| apache | jmeter | — | — |
| apache | jmeter | — | — |
| apache | jmeter | — | — |
| apache | jmeter | — | — |
| apache | jmeter | — | — |
| apache | jmeter | — | — |
| apache | jmeter | — | — |
| apache | jmeter | — | — |
| apache | jmeter | — | — |
| apache | jmeter | — | — |
| apache | jmeter | — | — |
| apache | jmeter | — | — |
| apache | jmeter | — | — |
| apache | jmeter | — | — |
| apache | jmeter | — | — |
| apache | jmeter | — | — |
| apache | jmeter | — | — |
| apache | jmeter | — | — |
| apache | jmeter | — | — |
| apache | jmeter | — | — |
| apache | jmeter | — | — |
| apache_software_foundation | apache_jmeter | — | — |
| apache_software_foundation | apache_jmeter | — | — |
| debian | jakarta-jmeter | — | — |
Detection & IOCsextracted from sources · hover to see the quote
- →Detect unsecured RMI connections targeting Apache JMeter's distributed test (RMI-based) interface, which may indicate exploitation of CVE-2018-1297 to access JMeterEngine and execute unauthorized code. ↗
- ·Vulnerability is scoped as local and remains open across multiple Debian releases (bookworm, bullseye, forky, sid, trixie), meaning patched packages may not be available via standard Debian repositories. ↗
- ·Only Apache JMeter 2.x and 3.x are affected when the Distributed Test (RMI-based) mode is in use; the unsecured RMI connection is a configuration/deployment concern rather than a code defect alone. ↗
CVSS provenance
nvdv3.09.8CRITICALCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
osv9.8CRITICAL
vendor_debian9.8LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
Missing certificate validation in Apache JMeter
ghsa·2022-05-13
CVE-2018-1297 [CRITICAL] CWE-319 Missing certificate validation in Apache JMeter
Missing certificate validation in Apache JMeter
When using Distributed Test only (RMI based), Apache JMeter 2.x and 3.x uses an unsecured RMI connection. This could allow an attacker to get Access to JMeterEngine and send unauthorized code.
OSV
Missing certificate validation in Apache JMeter
osv·2022-05-13
CVE-2018-1297 [CRITICAL] Missing certificate validation in Apache JMeter
Missing certificate validation in Apache JMeter
When using Distributed Test only (RMI based), Apache JMeter 2.x and 3.x uses an unsecured RMI connection. This could allow an attacker to get Access to JMeterEngine and send unauthorized code.
OSV
CVE-2018-1297: When using Distributed Test only (RMI based), Apache JMeter 2
osv·2018-02-13·CVSS 9.8
CVE-2018-1297 [CRITICAL] CVE-2018-1297: When using Distributed Test only (RMI based), Apache JMeter 2
When using Distributed Test only (RMI based), Apache JMeter 2.x and 3.x uses an unsecured RMI connection. This could allow an attacker to get Access to JMeterEngine and send unauthorized code.
Debian
CVE-2018-1297: jakarta-jmeter - When using Distributed Test only (RMI based), Apache JMeter 2.x and 3.x uses an ...
vendor_debian·2018·CVSS 9.8
CVE-2018-1297 [CRITICAL] CVE-2018-1297: jakarta-jmeter - When using Distributed Test only (RMI based), Apache JMeter 2.x and 3.x uses an ...
When using Distributed Test only (RMI based), Apache JMeter 2.x and 3.x uses an unsecured RMI connection. This could allow an attacker to get Access to JMeterEngine and send unauthorized code.
Scope: local
bookworm: open
bullseye: open
forky: open
sid: open
trixie: open
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://mail-archives.apache.org/mod_mbox/www-announce/201802.mbox/%3CCAH9fUpaNzk5am8oFe07RQ-kynCsQv54yB-uYs9bEnz7tbX-O7g%40mail.gmail.com%3Ehttps://bz.apache.org/bugzilla/show_bug.cgi?id=62039https://lists.apache.org/thread.html/31e0adbeca9d865ff74d0906b2248a41a1457cb54c1afbe5947df58b%40%3Cissues.jmeter.apache.org%3Ehttp://mail-archives.apache.org/mod_mbox/www-announce/201802.mbox/%3CCAH9fUpaNzk5am8oFe07RQ-kynCsQv54yB-uYs9bEnz7tbX-O7g%40mail.gmail.com%3Ehttps://bz.apache.org/bugzilla/show_bug.cgi?id=62039https://lists.apache.org/thread.html/31e0adbeca9d865ff74d0906b2248a41a1457cb54c1afbe5947df58b%40%3Cissues.jmeter.apache.org%3E
2018-02-13
Published