CVE-2018-1000130: High severity Jolokia Webarchive Agent vulnerability
Published Mar 14, 2018
·Updated
A JNDI Injection vulnerability exists in Jolokia agent version 1.3.7 in the proxy mode that allows a remote attacker to run arbitrary Java code on the server.
Affected Software
2 affected componentsFixes available
redhat/jolokia-core<1.5.0
1.5.0
Jolokia Webarchive Agent=1.3.7
Event History
Mar 14, 2018
CVE Published
via MITRE·01:00 PM
Data Sourced
via MITRE·01:00 PM
Description
Mar 22, 2018
Data Sourced
via Red Hat·09:43 AM
DescriptionSeverityAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2018-1000130?
The severity of CVE-2018-1000130 is high, with a CVSS score of 8.1.
2
How does CVE-2018-1000130 impact Jolokia agent version 1.3.7?
CVE-2018-1000130 allows a remote attacker to run arbitrary Java code on the server.
3
Which versions of Jolokia agent are affected by CVE-2018-1000130?
Jolokia agent version 1.3.7 is affected by CVE-2018-1000130.
4
How do I fix CVE-2018-1000130?
Update Jolokia agent to version 1.5.0 to fix CVE-2018-1000130.
5
Where can I find more information about CVE-2018-1000130?
You can find more information about CVE-2018-1000130 at the following references: [link1], [link2], [link3].