Логотип exploitDog
bind:CVE-2019-0187
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2019-0187

Количество 4

Количество 4

ubuntu логотип

CVE-2019-0187

почти 7 лет назад

Unauthenticated RCE is possible when JMeter is used in distributed mode (-r or -R command line options). Attacker can establish a RMI connection to a jmeter-server using RemoteJMeterEngine and proceed with an attack using untrusted data deserialization. This only affect tests running in Distributed mode. Note that versions before 4.0 are not able to encrypt traffic between the nodes, nor authenticate the participating nodes so upgrade to JMeter 5.1 is also advised.

CVSS3: 9.8
EPSS: Низкий
nvd логотип

CVE-2019-0187

почти 7 лет назад

Unauthenticated RCE is possible when JMeter is used in distributed mode (-r or -R command line options). Attacker can establish a RMI connection to a jmeter-server using RemoteJMeterEngine and proceed with an attack using untrusted data deserialization. This only affect tests running in Distributed mode. Note that versions before 4.0 are not able to encrypt traffic between the nodes, nor authenticate the participating nodes so upgrade to JMeter 5.1 is also advised.

CVSS3: 9.8
EPSS: Низкий
debian логотип

CVE-2019-0187

почти 7 лет назад

Unauthenticated RCE is possible when JMeter is used in distributed mod ...

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-wg37-7mrv-cfwm

почти 7 лет назад

Unauthenticated Remote Code Execution in Apache JMeter

CVSS3: 9.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2019-0187

Unauthenticated RCE is possible when JMeter is used in distributed mode (-r or -R command line options). Attacker can establish a RMI connection to a jmeter-server using RemoteJMeterEngine and proceed with an attack using untrusted data deserialization. This only affect tests running in Distributed mode. Note that versions before 4.0 are not able to encrypt traffic between the nodes, nor authenticate the participating nodes so upgrade to JMeter 5.1 is also advised.

CVSS3: 9.8
1%
Низкий
почти 7 лет назад
nvd логотип
CVE-2019-0187

Unauthenticated RCE is possible when JMeter is used in distributed mode (-r or -R command line options). Attacker can establish a RMI connection to a jmeter-server using RemoteJMeterEngine and proceed with an attack using untrusted data deserialization. This only affect tests running in Distributed mode. Note that versions before 4.0 are not able to encrypt traffic between the nodes, nor authenticate the participating nodes so upgrade to JMeter 5.1 is also advised.

CVSS3: 9.8
1%
Низкий
почти 7 лет назад
debian логотип
CVE-2019-0187

Unauthenticated RCE is possible when JMeter is used in distributed mod ...

CVSS3: 9.8
1%
Низкий
почти 7 лет назад
github логотип
GHSA-wg37-7mrv-cfwm

Unauthenticated Remote Code Execution in Apache JMeter

CVSS3: 9.8
1%
Низкий
почти 7 лет назад

Уязвимостей на страницу