PT-2018-11443 · Apache+1 · Apache Jmeter+1
Published
2018-02-14
·
Updated
2022-05-13
·
CVE-2018-1287
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Apache JMeter versions 2.X through 3.X
Description
The issue arises when Apache JMeter is used in Distributed Test mode, which is RMI-based. In this scenario, the jmeter server binds the RMI Registry to a wildcard host, potentially allowing an attacker to access the JMeterEngine and send unauthorized code. This vulnerability is based on the architectural assumption that JMeter is operating on a 'safe' network where all users with access are considered trusted.
Recommendations
For Apache JMeter versions 2.X through 3.X, consider restricting access to the RMI Registry to minimize the risk of exploitation, especially when operating in Distributed Test mode. As a temporary workaround, limit the network access to trusted users only, aligning with JMeter's architectural assumption of a 'safe' network.
Fix
Improper Verification of Cryptographic Signature
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Apache Jmeter
Debian