cbcvebase.
CVE-2018-1297
published 2018-02-13

CVE-2018-1297: When using Distributed Test only (RMI based), Apache JMeter 2.x and 3.x uses an unsecured RMI connection. This could allow an attacker to get Access to…

PriorityP357critical9.8CVSS 3.0
AVNACLPRNUINSUCHIHAH
EPSS
10.10%
95.1th percentile
When using Distributed Test only (RMI based), Apache JMeter 2.x and 3.x uses an unsecured RMI connection. This could allow an attacker to get Access to JMeterEngine and send unauthorized code.

Affected

25 ranges
VendorProductVersion rangeFixed in
apachejmeter
apachejmeter
apachejmeter
apachejmeter
apachejmeter
apachejmeter
apachejmeter
apachejmeter
apachejmeter
apachejmeter
apachejmeter
apachejmeter
apachejmeter
apachejmeter
apachejmeter
apachejmeter
apachejmeter
apachejmeter
apachejmeter
apachejmeter
apachejmeter
apachejmeter
apache_software_foundationapache_jmeter
apache_software_foundationapache_jmeter
debianjakarta-jmeter

Detection & IOCsextracted from sources · hover to see the quote

  • Detect unsecured RMI connections targeting Apache JMeter's distributed test (RMI-based) interface, which may indicate exploitation of CVE-2018-1297 to access JMeterEngine and execute unauthorized code.
  • ·Vulnerability is scoped as local and remains open across multiple Debian releases (bookworm, bullseye, forky, sid, trixie), meaning patched packages may not be available via standard Debian repositories.
  • ·Only Apache JMeter 2.x and 3.x are affected when the Distributed Test (RMI-based) mode is in use; the unsecured RMI connection is a configuration/deployment concern rather than a code defect alone.

CVSS provenance

nvdv3.09.8CRITICALCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
osv9.8CRITICAL
vendor_debian9.8LOW
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.