V
Scaner-VS
HomeCatalogSourcesCWECAPECATT&CKMitigationsDocs
CVE-2018-1297
DEB
CriticalConfirmedExploit available

When using Distributed Test only (RMI based), Apache JMeter 2.x and 3.x uses an unsecured RMI connection. This could allow an attacker to g…

CVSS
9.8
Critical
EPSS
0.18
p95
Published
2018-01-01
Updated
2018-01-01
Description

When using Distributed Test only (RMI based), Apache JMeter 2.x and 3.x uses an unsecured RMI connection. This could allow an attacker to get Access to JMeterEngine and send unauthorized code.

Tags · CWE
Pre-auth
CWE-319
CAPEC-65
CAPEC-102
CAPEC-117
CAPEC-383
CAPEC-477
Affected products
Jakarta-jmeterJakarta-jmeterJakarta-jmeterJakarta-jmeterJakarta-jmeterJakarta-jmeterJakarta-jmeterJakarta-jmeterJakarta-jmeterJakarta-jmeterJakarta-jmeterJakarta-jmeterJakarta-jmeterJakarta-jmeterJakarta-jmeterJakarta-jmeterJakarta-jmeterJakarta-jmeterJakarta-jmeterJakarta-jmeter
CVSS vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Timeline
2018-01-01
Published
2018-01-01
Updated
CVSS 3.1 breakdown
Attack Vector
AV: N
Network (N)
Attack Complexity
AC: L
Low (L)
Privileges Required
PR: N
None (N)
User Interaction
UI: N
None (N)
Scope
S: U
Unchanged (U)
Confidentiality Impact
C: H
High (H)
Integrity Impact
I: H
High (H)
Availability Impact
A: H
High (H)
Exploit indicators
EPSS
0.180 · p95
Known exploited (KEV)
No
MITRE ATT&CK
Inferred via CAPEC
└ via CAPEC-65 · CWE-319
└ via CAPEC-383 · CWE-319
Known exploits — Сканер-ВС
CVE-2018-1297
github-poc · https://github.com/48484848484848/Jmeter-CVE-2018-1297-
Enterprise
Affected software
ProductVendorStatus
jakarta-jmeterTracked
jakarta-jmeterTracked
jakarta-jmeterTracked
jakarta-jmeterTracked
jakarta-jmeterTracked
jakarta-jmeterTracked
jakarta-jmeterTracked
jakarta-jmeterTracked
jakarta-jmeterTracked
jakarta-jmeterTracked
jakarta-jmeterTracked
jakarta-jmeterTracked
jakarta-jmeterTracked
jakarta-jmeterTracked
jakarta-jmeterTracked
jakarta-jmeterTracked
jakarta-jmeterTracked
jakarta-jmeterTracked
jakarta-jmeterTracked
jakarta-jmeterTracked
Source databases
DEB
CVE
UBU