CVE-2020-1952

CRITICAL

Apache IoTDB 0.8.0-0.8.2 and 0.9.0-0.9.1 - Unauthenticated Remote Code Execution via JMX Port

Title source: llm
STIX 2.1

Description

An issue was found in Apache IoTDB .9.0 to 0.9.1 and 0.8.0 to 0.8.2. When starting IoTDB, the JMX port 31999 is exposed with no certification.Then, clients could execute code remotely.

Scores

CVSS v3 9.8
EPSS 0.0165
EPSS Percentile 82.3%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-295
Status published
Products (2)
apache/iotdb 0.8.0 - 0.8.2
org.apache.iotdb/iotdb-parent 0 - 0.9.2Maven
Published Apr 27, 2020
Tracked Since Feb 18, 2026