CVE-2018-1000130
Published · Updated
62Vexday Risk Score
Patch now. It exploitation observed by VulnCheck and has a working public exploit.
ssvc Actepss 74%
from disclosure to weapon
Published on NVDMar 14
VulnCheck+2121d
exploitation probability
74%top 1% of all CVEs
observed exploitation
yesVulnCheck
What the vendors declare (VEX)
Official vendor statements in CSAF/VEX format: whether their product is affected, already fixed, or ruled out — and why. These are the vendor's assertions, not Vexday's judgment.
Red HatVEX document ↗
Affected
9 products (10 components)
Red Hat OpenStack Platform 13 (Queens) · Red Hat AMQ Broker 7 · Red Hat JBoss A-MQ 6 · Red Hat JBoss Data Virtualization 6 · Red Hat JBoss Fuse 6 · and others 4
none_available: Affected
Fixed
Not affected
4 products — because the vulnerable code is not present in the product
JBoss Developer Studio 11 · Red Hat Enterprise Linux OpenStack Platform 7 (Kilo) · Red Hat OpenStack Platform 11 (Ocata) · Red Hat OpenStack Platform 8 (Liberty)
A JNDI Injection vulnerability exists in Jolokia agent version 1.3.7 in the proxy mode that allows a remote attacker to run arbitrary Java code on the server.
Affected products
n/a · n/a