CVE Vulnerabilities

CVE-2018-1297

Cleartext Transmission of Sensitive Information

Published: Feb 13, 2018 | Modified: Nov 21, 2024
CVSS 3.x
9.8
CRITICAL
Source:
NVD
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS 2.x
7.5 HIGH
AV:N/AC:L/Au:N/C:P/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu
MEDIUM

When using Distributed Test only (RMI based), Apache JMeter 2.x and 3.x uses an unsecured RMI connection. This could allow an attacker to get Access to JMeterEngine and send unauthorized code.

Weakness

The product transmits sensitive or security-critical data in cleartext in a communication channel that can be sniffed by unauthorized actors.

Affected Software

Name Vendor Start Version End Version
Jmeter Apache 2.1 (including) 2.1 (including)
Jmeter Apache 2.2 (including) 2.2 (including)
Jmeter Apache 2.3 (including) 2.3 (including)
Jmeter Apache 2.3.1 (including) 2.3.1 (including)
Jmeter Apache 2.3.2 (including) 2.3.2 (including)
Jmeter Apache 2.3.3 (including) 2.3.3 (including)
Jmeter Apache 2.3.3-rc1 (including) 2.3.3-rc1 (including)
Jmeter Apache 2.3.3-rc2 (including) 2.3.3-rc2 (including)
Jmeter Apache 2.3.4 (including) 2.3.4 (including)
Jmeter Apache 2.3.4-rc1 (including) 2.3.4-rc1 (including)
Jmeter Apache 2.3.4-rc2 (including) 2.3.4-rc2 (including)
Jmeter Apache 2.3.4-rc3 (including) 2.3.4-rc3 (including)
Jmeter Apache 2.4 (including) 2.4 (including)
Jmeter Apache 2.5 (including) 2.5 (including)
Jmeter Apache 2.5-rc1 (including) 2.5-rc1 (including)
Jmeter Apache 2.5-rc2 (including) 2.5-rc2 (including)
Jmeter Apache 2.5-rc3 (including) 2.5-rc3 (including)
Jmeter Apache 2.5.1 (including) 2.5.1 (including)
Jmeter Apache 2.5.1-rc1 (including) 2.5.1-rc1 (including)
Jmeter Apache 2.5.1-rc2 (including) 2.5.1-rc2 (including)
Jmeter Apache 2.5.1-rc3 (including) 2.5.1-rc3 (including)
Jmeter Apache 2.6 (including) 2.6 (including)
Jmeter Apache 2.6-rc1 (including) 2.6-rc1 (including)
Jmeter Apache 2.6-rc2 (including) 2.6-rc2 (including)
Jmeter Apache 2.7 (including) 2.7 (including)
Jmeter Apache 2.7-rc1 (including) 2.7-rc1 (including)
Jmeter Apache 2.7-rc2 (including) 2.7-rc2 (including)
Jmeter Apache 2.7-rc3 (including) 2.7-rc3 (including)
Jmeter Apache 2.8 (including) 2.8 (including)
Jmeter Apache 2.8-rc1 (including) 2.8-rc1 (including)
Jmeter Apache 2.8-rc2 (including) 2.8-rc2 (including)
Jmeter Apache 2.9 (including) 2.9 (including)
Jmeter Apache 2.9-rc1 (including) 2.9-rc1 (including)
Jmeter Apache 2.9-rc2 (including) 2.9-rc2 (including)
Jmeter Apache 2.9-rc3 (including) 2.9-rc3 (including)
Jmeter Apache 2.10-rc1 (including) 2.10-rc1 (including)
Jmeter Apache 2.10-rc2 (including) 2.10-rc2 (including)
Jmeter Apache 2.11 (including) 2.11 (including)
Jmeter Apache 2.11-rc1 (including) 2.11-rc1 (including)
Jmeter Apache 2.11-rc2 (including) 2.11-rc2 (including)
Jmeter Apache 2.12 (including) 2.12 (including)
Jmeter Apache 2.12-rc1 (including) 2.12-rc1 (including)
Jmeter Apache 2.12-rc2 (including) 2.12-rc2 (including)
Jmeter Apache 2.13 (including) 2.13 (including)
Jmeter Apache 2.13-rc1 (including) 2.13-rc1 (including)
Jmeter Apache 2.13-rc2 (including) 2.13-rc2 (including)
Jmeter Apache 3.0 (including) 3.0 (including)
Jmeter Apache 3.0-rc1 (including) 3.0-rc1 (including)
Jmeter Apache 3.0-rc2 (including) 3.0-rc2 (including)
Jmeter Apache 3.0-rc3 (including) 3.0-rc3 (including)
Jmeter Apache 3.0-rc4 (including) 3.0-rc4 (including)
Jmeter Apache 3.0-rc5 (including) 3.0-rc5 (including)
Jmeter Apache 3.1 (including) 3.1 (including)
Jmeter Apache 3.1-rc1 (including) 3.1-rc1 (including)
Jmeter Apache 3.1-rc2 (including) 3.1-rc2 (including)
Jmeter Apache 3.1-rc3 (including) 3.1-rc3 (including)
Jmeter Apache 3.1-rc4 (including) 3.1-rc4 (including)
Jmeter Apache 3.2 (including) 3.2 (including)
Jmeter Apache 3.2-rc1 (including) 3.2-rc1 (including)
Jmeter Apache 3.2-rc2 (including) 3.2-rc2 (including)
Jmeter Apache 3.2-rc3 (including) 3.2-rc3 (including)
Jmeter Apache 3.3 (including) 3.3 (including)
Jmeter Apache 3.3-rc1 (including) 3.3-rc1 (including)
Jakarta-jmeter Ubuntu artful *
Jakarta-jmeter Ubuntu bionic *
Jakarta-jmeter Ubuntu cosmic *
Jakarta-jmeter Ubuntu disco *
Jakarta-jmeter Ubuntu eoan *
Jakarta-jmeter Ubuntu focal *
Jakarta-jmeter Ubuntu groovy *
Jakarta-jmeter Ubuntu hirsute *
Jakarta-jmeter Ubuntu impish *
Jakarta-jmeter Ubuntu kinetic *
Jakarta-jmeter Ubuntu lunar *
Jakarta-jmeter Ubuntu mantic *
Jakarta-jmeter Ubuntu oracular *
Jakarta-jmeter Ubuntu trusty *
Jakarta-jmeter Ubuntu xenial *

Potential Mitigations

References