CVE-2018-1000130: Jolokia Webarchive Agent

High severity, CVSS 8.1. EPSS: 74% chance of exploitation in the next 30 days.

A JNDI Injection vulnerability exists in Jolokia agent version 1.3.7 in the proxy mode that allows a remote attacker to run arbitrary Java code on the server.

Affected products

  • Jolokia Webarchive Agent: version 1.3.7 only

Published 2018-03-14. Last modified 2026-06-17.