CVE-2018-1000130observed exploitation

CVE-2018-1000130

Published · Updated

62Vexday Risk Score

Patch now. It exploitation observed by VulnCheck and has a working public exploit.

ssvc Actepss 74%
from disclosure to weapon
Published on NVDMar 14
VulnCheck+2121d
exploitation probability
74%top 1% of all CVEs
observed exploitation
yesVulnCheck
What the vendors declare (VEX)

Official vendor statements in CSAF/VEX format: whether their product is affected, already fixed, or ruled out — and why. These are the vendor's assertions, not Vexday's judgment.

Affected
9 products (10 components)
Red Hat OpenStack Platform 13 (Queens) · Red Hat AMQ Broker 7 · Red Hat JBoss A-MQ 6 · Red Hat JBoss Data Virtualization 6 · Red Hat JBoss Fuse 6 · and others 4
none_available: Affected
Fixed
1 product
Red Hat JBoss Fuse 7
Not affected
4 products — because the vulnerable code is not present in the product
JBoss Developer Studio 11 · Red Hat Enterprise Linux OpenStack Platform 7 (Kilo) · Red Hat OpenStack Platform 11 (Ocata) · Red Hat OpenStack Platform 8 (Liberty)
A JNDI Injection vulnerability exists in Jolokia agent version 1.3.7 in the proxy mode that allows a remote attacker to run arbitrary Java code on the server.
Affected products
n/a · n/a