CVE-2018-1287

Summary

In Apache JMeter 2.X and 3.X, when using Distributed Test only (RMI based), jmeter server binds RMI Registry to wildcard host. This could allow an attacker to get Access to JMeterEngine and send unauthorized code.

Affected Software

VendorProductVersion RangeStatus
Apache Software FoundationApache JMeter2.xaffected
Apache Software FoundationApache JMeter3.xaffected

Weaknesses

  • Unauthorized code execution

ADP Enrichment

CVE Program Container

Additional References

References