CVE-2018-1000130

Severity CVSS v4.0:
Pending analysis
Type:
CWE-74 Injection
Publication date:
14/03/2018
Last modified:
08/03/2019

Description

A JNDI Injection vulnerability exists in Jolokia agent version 1.3.7 in the proxy mode that allows a remote attacker to run arbitrary Java code on the server.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:jolokia:webarchive_agent:1.3.7:*:*:*:*:*:*:*