ZeroHour

CVE-2018-1287

CVSS 3.0
9.8 critical
EPSS
3%p88
Published
()
Modified
Description

In Apache JMeter 2.X and 3.X, when using Distributed Test only (RMI based), jmeter server binds RMI Registry to wildcard host. This could allow an attacker to get Access to JMeterEngine and send unauthorized code.

Vendors
apache
Products
jmeter
Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.