CVE-2018-1287: Apache JMeter binds RMI server to wildcard in distributed mode (based on RMI)
Vendor: The Apache Software Foundation
Versions Affected: JMeter 2.X, 3.X
When using Distributed Test only (RMI based), jmeter server binds RMI
Registry to wildcard host.
This could allow an attacker to get Access to JMeterEngine and send
This only affect tests running in Distributed mode.
* Users must use last version of Java 8 or Java 9
* Users must upgrade to last JMeter 4.0 version
Besides, we remind users that in distributed mode, JMeter makes an
that it is operating on a 'safe' network. i.e. everyone with access to the
network is considered trusted.
This typically means a dedicated VPN or similar is being used.
* Start JMeter server using either jmeter-server or jmeter -s
* If JMeter listens on *:1099, you are vulnerable
This issue was reported responsibly to the Apache Tomcat Security Team
by Brenden Meeder.