CVE Vulnerabilities

CVE-2018-1297

Cleartext Transmission of Sensitive Information

Published: Feb 13, 2018 | Modified: Nov 21, 2024
CVSS 3.x
9.8
CRITICAL
Source:
NVD
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS 2.x
7.5 HIGH
AV:N/AC:L/Au:N/C:P/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

When using Distributed Test only (RMI based), Apache JMeter 2.x and 3.x uses an unsecured RMI connection. This could allow an attacker to get Access to JMeterEngine and send unauthorized code.

Weakness

The product transmits sensitive or security-critical data in cleartext in a communication channel that can be sniffed by unauthorized actors.

Affected Software

NameVendorStart VersionEnd Version
JmeterApache2.1 (including)2.1 (including)
JmeterApache2.2 (including)2.2 (including)
JmeterApache2.3 (including)2.3 (including)
JmeterApache2.3.1 (including)2.3.1 (including)
JmeterApache2.3.2 (including)2.3.2 (including)
JmeterApache2.3.3 (including)2.3.3 (including)
JmeterApache2.3.3-rc1 (including)2.3.3-rc1 (including)
JmeterApache2.3.3-rc2 (including)2.3.3-rc2 (including)
JmeterApache2.3.4 (including)2.3.4 (including)
JmeterApache2.3.4-rc1 (including)2.3.4-rc1 (including)
JmeterApache2.3.4-rc2 (including)2.3.4-rc2 (including)
JmeterApache2.3.4-rc3 (including)2.3.4-rc3 (including)
JmeterApache2.4 (including)2.4 (including)
JmeterApache2.5 (including)2.5 (including)
JmeterApache2.5-rc1 (including)2.5-rc1 (including)
JmeterApache2.5-rc2 (including)2.5-rc2 (including)
JmeterApache2.5-rc3 (including)2.5-rc3 (including)
JmeterApache2.5.1 (including)2.5.1 (including)
JmeterApache2.5.1-rc1 (including)2.5.1-rc1 (including)
JmeterApache2.5.1-rc2 (including)2.5.1-rc2 (including)
JmeterApache2.5.1-rc3 (including)2.5.1-rc3 (including)
JmeterApache2.6 (including)2.6 (including)
JmeterApache2.6-rc1 (including)2.6-rc1 (including)
JmeterApache2.6-rc2 (including)2.6-rc2 (including)
JmeterApache2.7 (including)2.7 (including)
JmeterApache2.7-rc1 (including)2.7-rc1 (including)
JmeterApache2.7-rc2 (including)2.7-rc2 (including)
JmeterApache2.7-rc3 (including)2.7-rc3 (including)
JmeterApache2.8 (including)2.8 (including)
JmeterApache2.8-rc1 (including)2.8-rc1 (including)
JmeterApache2.8-rc2 (including)2.8-rc2 (including)
JmeterApache2.9 (including)2.9 (including)
JmeterApache2.9-rc1 (including)2.9-rc1 (including)
JmeterApache2.9-rc2 (including)2.9-rc2 (including)
JmeterApache2.9-rc3 (including)2.9-rc3 (including)
JmeterApache2.10-rc1 (including)2.10-rc1 (including)
JmeterApache2.10-rc2 (including)2.10-rc2 (including)
JmeterApache2.11 (including)2.11 (including)
JmeterApache2.11-rc1 (including)2.11-rc1 (including)
JmeterApache2.11-rc2 (including)2.11-rc2 (including)
JmeterApache2.12 (including)2.12 (including)
JmeterApache2.12-rc1 (including)2.12-rc1 (including)
JmeterApache2.12-rc2 (including)2.12-rc2 (including)
JmeterApache2.13 (including)2.13 (including)
JmeterApache2.13-rc1 (including)2.13-rc1 (including)
JmeterApache2.13-rc2 (including)2.13-rc2 (including)
JmeterApache3.0 (including)3.0 (including)
JmeterApache3.0-rc1 (including)3.0-rc1 (including)
JmeterApache3.0-rc2 (including)3.0-rc2 (including)
JmeterApache3.0-rc3 (including)3.0-rc3 (including)
JmeterApache3.0-rc4 (including)3.0-rc4 (including)
JmeterApache3.0-rc5 (including)3.0-rc5 (including)
JmeterApache3.1 (including)3.1 (including)
JmeterApache3.1-rc1 (including)3.1-rc1 (including)
JmeterApache3.1-rc2 (including)3.1-rc2 (including)
JmeterApache3.1-rc3 (including)3.1-rc3 (including)
JmeterApache3.1-rc4 (including)3.1-rc4 (including)
JmeterApache3.2 (including)3.2 (including)
JmeterApache3.2-rc1 (including)3.2-rc1 (including)
JmeterApache3.2-rc2 (including)3.2-rc2 (including)
JmeterApache3.2-rc3 (including)3.2-rc3 (including)
JmeterApache3.3 (including)3.3 (including)
JmeterApache3.3-rc1 (including)3.3-rc1 (including)
Jakarta-jmeterUbuntuartful*
Jakarta-jmeterUbuntubionic*
Jakarta-jmeterUbuntucosmic*
Jakarta-jmeterUbuntudisco*
Jakarta-jmeterUbuntueoan*
Jakarta-jmeterUbuntufocal*
Jakarta-jmeterUbuntugroovy*
Jakarta-jmeterUbuntuhirsute*
Jakarta-jmeterUbuntuimpish*
Jakarta-jmeterUbuntukinetic*
Jakarta-jmeterUbuntulunar*
Jakarta-jmeterUbuntumantic*
Jakarta-jmeterUbuntuoracular*
Jakarta-jmeterUbuntuplucky*
Jakarta-jmeterUbuntutrusty*
Jakarta-jmeterUbuntuxenial*

Potential Mitigations

References