CVE-2018-1297

Description

When using Distributed Test only (RMI based), Apache JMeter 2.x and 3.x uses an unsecured RMI connection. This could allow an attacker to get Access to JMeterEngine and send unauthorized code.

Risk Information

Base Score
9.8
MODERATE
Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS Score
Exploitation Probability
17.994

Associated Vulnerability

VulnerabilityOS Platform
Vulnerabilities CVE-2018-1297,CVE-2018-1287 are fixed in Apache-ApacheJMeter 4.0Windows
Vulnerabilities CVE-2018-1297,CVE-2018-1287 are fixed in Apache-ApacheJMeter for Linux 4.0Linux

Patch Details

No records found

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234