CVE-2018-1287: Apache Jmeter
Critical severity, CVSS 9.8. EPSS: 3.4% chance of exploitation in the next 30 days.
In Apache JMeter 2.X and 3.X, when using Distributed Test only (RMI based), jmeter server binds RMI Registry to wildcard host. This could allow an attacker to get Access to JMeterEngine and send unauthorized code.
Affected products
- Apache Jmeter: version 2.1 only; version 2.2 only; version 2.3 only; version 2.3.1 only; version 2.3.2 only; version 2.3.3 only; …
Published 2018-02-14. Last modified 2026-06-17.