First published: Wed Mar 14 2018(Updated: )
A JNDI Injection vulnerability exists in Jolokia agent version 1.3.7 in the proxy mode that allows a remote attacker to run arbitrary Java code on the server.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Jolokia Webarchive Agent | =1.3.7 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2018-1000130 is high, with a CVSS score of 8.1.
CVE-2018-1000130 allows a remote attacker to run arbitrary Java code on the server.
Jolokia agent version 1.3.7 is affected by CVE-2018-1000130.
Update Jolokia agent to version 1.5.0 to fix CVE-2018-1000130.
You can find more information about CVE-2018-1000130 at the following references: [link1], [link2], [link3].