CVE-2018-1297: Apache Jmeter
Critical severity, CVSS 9.8. EPSS: 11.4% chance of exploitation in the next 30 days.
When using Distributed Test only (RMI based), Apache JMeter 2.x and 3.x uses an unsecured RMI connection. This could allow an attacker to get Access to JMeterEngine and send unauthorized code.
Affected products
- Apache Jmeter: version 2.1 only; version 2.2 only; version 2.3 only; version 2.3.1 only; version 2.3.2 only; version 2.3.3 only; …
Published 2018-02-13. Last modified 2026-06-17.