CVE-2019-0187
Last modified
CVE-2019-0187 is a vulnerability of currently unknown severity. Unauthenticated RCE is possible when JMeter is used in distributed mode (-r or -R command line options). Attacker can establish a RMI connection to a jmeter-server using RemoteJMeterEngine and proceed with an attack using untrusted data deserialization. EPSS estimates a 2.71% chance of exploitation in the next 30 days.
Description
Unauthenticated RCE is possible when JMeter is used in distributed mode (-r or -R command line options). Attacker can establish a RMI connection to a jmeter-server using RemoteJMeterEngine and proceed with an attack using untrusted data deserialization. This only affect tests running in Distributed mode. Note that versions before 4.0 are not able to encrypt traffic between the nodes, nor authenticate the participating nodes so upgrade to JMeter 5.1 is also advised.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Apache | Jmeter | 4.0 |
| Apache | Jmeter | 5.0 |
References
- http://www.securityfocus.com/bid/107219Third Party Advisory, VDB Entry
- http://www.securityfocus.com/bid/107219Third Party Advisory, VDB Entry
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2019-0187?
How severe is CVE-2019-0187?
How do I fix CVE-2019-0187?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2019
- CVE-2019-0181Insufficient password protection in the attestation database…6.7
- CVE-2019-0182Insufficient password protection in the attestation database…3.3
- CVE-2019-0183Insufficient password protection in the attestation database…3.3
- CVE-2019-0184Insufficient access control in protected memory subsystem fo…5.5
- CVE-2019-0185Insufficient access control in protected memory subsystem fo…5.5
- CVE-2019-0186The input fields of the Apache Pluto "Chat Room" demo portle…
- CVE-2019-0188Apache Camel prior to 2.24.0 contains an XML external entity…7.5
- CVE-2019-0189The java.io.ObjectInputStream is known to cause Java seriali…9.8
- CVE-2019-0190A bug exists in the way mod_ssl handled client renegotiation…7.5
- CVE-2019-0191Apache Karaf kar deployer reads .kar archives and extracts t…
- CVE-2019-0192In Apache Solr versions 5.0.0 to 5.5.5 and 6.0.0 to 6.6.5, t…
- CVE-2019-0193In Apache Solr, the DataImportHandler, an optional but popul…7.2
Are you affected by CVE-2019-0187?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
