Куда я попал?
SECURITM это SGRC система, ? автоматизирующая процессы в службах информационной безопасности. SECURITM помогает построить и управлять ИСПДн, КИИ, ГИС, СМИБ/СУИБ, банковскими системами защиты.
А еще SECURITM это место для обмена опытом и наработками для служб безопасности.

CVE-2026-84218

PUBLISHED 02.09.2026

CNA: redhat

Org.jolokia/jolokia-core: incomplete jndi denylist in jolokia jsr-160 proxy (bypass of cve-2018-1000130 fix)

Обновлено: 02.09.2026
A flaw was found in Jolokia's JSR-160 proxy functionality where insufficient validation of client-controlled JMX service URLs allows a bypass of the denylist introduced to mitigate CVE-2018-1000130. The proxy accepts a `target.url` value from a Jolokia POST request and passes it to `JMXServiceURL` and `JMXConnectorFactory` for establishing the remote JMX connection. The existing denylist only rejects URLs matching `service:jmx:rmi:///jndi/ldap:.*`, which can be bypassed using alternative valid JMX service URL forms, including `ldaps://` schemes or LDAP URLs with a non-empty JMX host component. These URLs are accepted as valid `JMXServiceURL` objects and can cause the Jolokia agent JVM to perform a JNDI lookup against an attacker-controlled LDAP endpoint. This can result in server-side request forgery (SSRF), forwarding of supplied JMX credentials to the remote endpoint, and potentially remote code execution depending on the classes and configuration available in the target JVM.

CWE

Идентификатор Описание
CWE-184 The product implements a protection mechanism that relies on a list of inputs (or properties of inputs) that are not allowed by policy or otherwise require other action to neutralize before additional processing takes place, but the list is incomplete.

CVSS

Оценка Severity Версия Базовый вектор
8.1 HIGH 3.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H

EPSS

Вероятность Severity Процентиль ? Дата расчёта
0.88% LOW 57.38 17.09.2026

Доп. Информация

Product Status

Red Hat AMQ Broker 7
Product: Red Hat AMQ Broker 7
Vendor: Red Hat
Default status: affected
СPE:
  • cpe:/a:redhat:amq_broker:7
Red Hat build of Apache Camel 4 for Quarkus 3
Product: Red Hat build of Apache Camel 4 for Quarkus 3
Vendor: Red Hat
Default status: unknown
СPE:
  • cpe:/a:redhat:camel_quarkus:3
Red Hat build of Apache Camel 4 for Quarkus 3
Product: Red Hat build of Apache Camel 4 for Quarkus 3
Vendor: Red Hat
Default status: unknown
СPE:
  • cpe:/a:redhat:camel_quarkus:3
Red Hat build of Apache Camel for Spring Boot 4
Product: Red Hat build of Apache Camel for Spring Boot 4
Vendor: Red Hat
Default status: unknown
СPE:
  • cpe:/a:redhat:camel_spring_boot:4
Red Hat build of Apache Camel for Spring Boot 4
Product: Red Hat build of Apache Camel for Spring Boot 4
Vendor: Red Hat
Default status: unknown
СPE:
  • cpe:/a:redhat:camel_spring_boot:4
Red Hat Fuse 7
Product: Red Hat Fuse 7
Vendor: Red Hat
Default status: unknown
СPE:
  • cpe:/a:redhat:jboss_fuse:7
Red Hat Satellite 6
Product: Red Hat Satellite 6
Vendor: Red Hat
Default status: unaffected
СPE:
  • cpe:/a:redhat:satellite:6
Red Hat Satellite 6
Product: Red Hat Satellite 6
Vendor: Red Hat
Default status: unaffected
СPE:
  • cpe:/a:redhat:satellite:6
 

Ссылки

CISA ADP Vulnrichment

Обновлено: 01.09.2026
Этот блок содержит дополнительную информацию, предоставленную программой CVE для этой уязвимости.

SSVC

Exploitation Automatable Technical Impact Версия Дата доступа
none no total 2.0.3 01.09.2026

Мы используем cookie-файлы, чтобы получить статистику, которая помогает нам улучшить сервис для вас с целью персонализации сервисов и предложений. Вы может прочитать подробнее о cookie-файлах или изменить настройки браузера. Продолжая пользоваться сайтом, вы даёте согласие на использование ваших cookie-файлов и соглашаетесь с Политикой обработки персональных данных.