CVE Vulnerabilities

CVE-2018-1287

Published: Feb 14, 2018 | Modified: Nov 21, 2024
CVSS 3.x
9.8
CRITICAL
Source:
NVD
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS 2.x
7.5 HIGH
AV:N/AC:L/Au:N/C:P/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu
MEDIUM

In Apache JMeter 2.X and 3.X, when using Distributed Test only (RMI based), jmeter server binds RMI Registry to wildcard host. This could allow an attacker to get Access to JMeterEngine and send unauthorized code.

Affected Software

Name Vendor Start Version End Version
Jmeter Apache 2.1 (including) 2.1 (including)
Jmeter Apache 2.2 (including) 2.2 (including)
Jmeter Apache 2.3 (including) 2.3 (including)
Jmeter Apache 2.3.1 (including) 2.3.1 (including)
Jmeter Apache 2.3.2 (including) 2.3.2 (including)
Jmeter Apache 2.3.3 (including) 2.3.3 (including)
Jmeter Apache 2.3.3-rc1 (including) 2.3.3-rc1 (including)
Jmeter Apache 2.3.3-rc2 (including) 2.3.3-rc2 (including)
Jmeter Apache 2.3.4 (including) 2.3.4 (including)
Jmeter Apache 2.3.4-rc1 (including) 2.3.4-rc1 (including)
Jmeter Apache 2.3.4-rc2 (including) 2.3.4-rc2 (including)
Jmeter Apache 2.3.4-rc3 (including) 2.3.4-rc3 (including)
Jmeter Apache 2.4 (including) 2.4 (including)
Jmeter Apache 2.5 (including) 2.5 (including)
Jmeter Apache 2.5-rc1 (including) 2.5-rc1 (including)
Jmeter Apache 2.5-rc2 (including) 2.5-rc2 (including)
Jmeter Apache 2.5-rc3 (including) 2.5-rc3 (including)
Jmeter Apache 2.5.1 (including) 2.5.1 (including)
Jmeter Apache 2.5.1-rc1 (including) 2.5.1-rc1 (including)
Jmeter Apache 2.5.1-rc2 (including) 2.5.1-rc2 (including)
Jmeter Apache 2.5.1-rc3 (including) 2.5.1-rc3 (including)
Jmeter Apache 2.6 (including) 2.6 (including)
Jmeter Apache 2.6-rc1 (including) 2.6-rc1 (including)
Jmeter Apache 2.6-rc2 (including) 2.6-rc2 (including)
Jmeter Apache 2.7 (including) 2.7 (including)
Jmeter Apache 2.7-rc1 (including) 2.7-rc1 (including)
Jmeter Apache 2.7-rc2 (including) 2.7-rc2 (including)
Jmeter Apache 2.7-rc3 (including) 2.7-rc3 (including)
Jmeter Apache 2.8 (including) 2.8 (including)
Jmeter Apache 2.8-rc1 (including) 2.8-rc1 (including)
Jmeter Apache 2.8-rc2 (including) 2.8-rc2 (including)
Jmeter Apache 2.9 (including) 2.9 (including)
Jmeter Apache 2.9-rc1 (including) 2.9-rc1 (including)
Jmeter Apache 2.9-rc2 (including) 2.9-rc2 (including)
Jmeter Apache 2.9-rc3 (including) 2.9-rc3 (including)
Jmeter Apache 2.10-rc1 (including) 2.10-rc1 (including)
Jmeter Apache 2.10-rc2 (including) 2.10-rc2 (including)
Jmeter Apache 2.11 (including) 2.11 (including)
Jmeter Apache 2.11-rc1 (including) 2.11-rc1 (including)
Jmeter Apache 2.11-rc2 (including) 2.11-rc2 (including)
Jmeter Apache 2.12 (including) 2.12 (including)
Jmeter Apache 2.12-rc1 (including) 2.12-rc1 (including)
Jmeter Apache 2.12-rc2 (including) 2.12-rc2 (including)
Jmeter Apache 2.13 (including) 2.13 (including)
Jmeter Apache 2.13-rc1 (including) 2.13-rc1 (including)
Jmeter Apache 2.13-rc2 (including) 2.13-rc2 (including)
Jmeter Apache 3.0 (including) 3.0 (including)
Jmeter Apache 3.0-rc1 (including) 3.0-rc1 (including)
Jmeter Apache 3.0-rc2 (including) 3.0-rc2 (including)
Jmeter Apache 3.0-rc3 (including) 3.0-rc3 (including)
Jmeter Apache 3.0-rc4 (including) 3.0-rc4 (including)
Jmeter Apache 3.0-rc5 (including) 3.0-rc5 (including)
Jmeter Apache 3.1 (including) 3.1 (including)
Jmeter Apache 3.1-rc1 (including) 3.1-rc1 (including)
Jmeter Apache 3.1-rc2 (including) 3.1-rc2 (including)
Jmeter Apache 3.1-rc3 (including) 3.1-rc3 (including)
Jmeter Apache 3.1-rc4 (including) 3.1-rc4 (including)
Jmeter Apache 3.2 (including) 3.2 (including)
Jmeter Apache 3.2-rc1 (including) 3.2-rc1 (including)
Jmeter Apache 3.2-rc2 (including) 3.2-rc2 (including)
Jmeter Apache 3.2-rc3 (including) 3.2-rc3 (including)
Jmeter Apache 3.3 (including) 3.3 (including)
Jmeter Apache 3.3-rc1 (including) 3.3-rc1 (including)
Jakarta-jmeter Ubuntu artful *
Jakarta-jmeter Ubuntu bionic *
Jakarta-jmeter Ubuntu cosmic *
Jakarta-jmeter Ubuntu disco *
Jakarta-jmeter Ubuntu eoan *
Jakarta-jmeter Ubuntu groovy *
Jakarta-jmeter Ubuntu hirsute *
Jakarta-jmeter Ubuntu impish *
Jakarta-jmeter Ubuntu kinetic *
Jakarta-jmeter Ubuntu lunar *
Jakarta-jmeter Ubuntu mantic *
Jakarta-jmeter Ubuntu trusty *
Jakarta-jmeter Ubuntu xenial *

References