[0day-rubbish] Lightstreamer Server 7.4.8 Unauthenticated JMX jvmtiAgentLoad native code execution (8.1)
Researchers disclosed an unauthenticated JMX flaw in Lightstreamer Server 7.4.8 that can load native code in the JVM.
The 0day Rubbish Research Team disclosed an unauthenticated access flaw in Lightstreamer Server 7.4.8 build 3506 with JMS Extender 2.1.0. An anonymous caller can use the JMX inspection console to invoke MBean operations, including loading a native agent into the broker JVM. The report cites CWE-306, CWE-345, CWE-20, CWE-250 and CWE-1188 and scores the issue 8.1. No CVE or in-the-wild exploitation is mentioned.