CVE Database
/

CVE-2019-0187

Back to search

CVE-2019-0187

Published: Mar 6, 2019

Modified: Sep 16, 2024

PUBLISHED

Description

Unauthenticated RCE is possible when JMeter is used in distributed mode (-r or -R command line options). Attacker can establish a RMI connection to a jmeter-server using RemoteJMeterEngine and proceed with an attack using untrusted data deserialization. This only affect tests running in Distributed mode. Note that versions before 4.0 are not able to encrypt traffic between the nodes, nor authenticate the participating nodes so upgrade to JMeter 5.1 is also advised.

VendorProductVersions

Apache Software Foundation

Apache JMeter

affected
Apache JMeter 4.0 to 5.0

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now