PT-2018-11443 · Apache+1 · Apache Jmeter+1

Published

2018-02-14

·

Updated

2022-05-13

·

CVE-2018-1287

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Apache JMeter versions 2.X through 3.X
Description The issue arises when Apache JMeter is used in Distributed Test mode, which is RMI-based. In this scenario, the jmeter server binds the RMI Registry to a wildcard host, potentially allowing an attacker to access the JMeterEngine and send unauthorized code. This vulnerability is based on the architectural assumption that JMeter is operating on a 'safe' network where all users with access are considered trusted.
Recommendations For Apache JMeter versions 2.X through 3.X, consider restricting access to the RMI Registry to minimize the risk of exploitation, especially when operating in Distributed Test mode. As a temporary workaround, limit the network access to trusted users only, aligning with JMeter's architectural assumption of a 'safe' network.

Fix

Improper Verification of Cryptographic Signature

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2018-1287
GHSA-J7J7-G4WW-PXG5

Affected Products

Apache Jmeter
Debian