jolokia Vulnerabilities and Affected Products
Explore source-attributed vulnerabilities associated with jolokia products.
Products
- jolokia1 vulnerability
- webarchive_agent1 vulnerability
| Vulnerability | Title and context | CVSS | EPSS | PoCs | Signals | STIX action |
|---|---|---|---|---|---|---|
CVE-2018-10899HIGH | Cross-Site Request Forgery in JolokiaA flaw was found in Jolokia versions from 1.2 to before 1.6.1. Affected versions are vulnerable to a system-wide CSRF. This holds true for properly configured instances with strict checking for origin and referrer headers. This could result in a Remote Code Execution attack. | CVSS8.1v3.0 | EPSS2.67% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2018-1000130HIGH | Injection in Jolokia agentA JNDI Injection vulnerability exists in Jolokia agent version 1.3.7 in the proxy mode that allows a remote attacker to run arbitrary Java code on the server. | CVSS8.1v3.0 | EPSS73.2% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware use1 Nuclei template | STIX |