Skip to main content

Vendor/product archive

apache / jmeter CVEs

Beta · best-effort

14 CVEs tagged to apache / jmeter3 Critical, 1 High, 10 Medium, 0 Low, 0 Unrated.

CVE-2019-0187

Published Mar 6, 2019

Unauthenticated RCE is possible when JMeter is used in distributed mode (-r or -R command line options). Attacker can establish a RMI connection to a jmeter-server using RemoteJMe…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2018-1287

Published Feb 14, 2018

In Apache JMeter 2.X and 3.X, when using Distributed Test only (RMI based), jmeter server binds RMI Registry to wildcard host. This could allow an attacker to get Access to JMeter…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2018-1297

Published Feb 13, 2018

When using Distributed Test only (RMI based), Apache JMeter 2.x and 3.x uses an unsecured RMI connection. This could allow an attacker to get Access to JMeterEngine and send unaut…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort
Showing 1-14 of 14 CVEsPage 1 of 1