Jmeter

Vendor:

First CVE: Feb 13, 2018 · Active for 8 years

14
Total CVEs
More Total CVEs than 91% of tracked products
4.7
Avg CVEs / Year
Higher CVE frequency than 87% of tracked products
9.1
Avg CVSS
Higher Avg CVSS than 85% of tracked products
0.0%
KEV Rate
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact Jmeter over time

Volume of CVEsAvg CVSS Base Score
First CVE
Feb 13, 2018
8 years ago
Most Recent CVE
Mar 23, 2021
1,949 days ago

CVE Severity & Scoring

Jmeter14 CVEs
All CVEs352,231 CVEs
HighCritical
Attack Vector
Local0 (0.0%)
Network14 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low14 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None14 (100.0%)
Unknown0 (0.0%)
Required0 (0.0%)
Privileges Required
Low1 (7.1%)
High1 (7.1%)
None12 (85.7%)
Unknown0 (0.0%)

Top CVEs

Signals from CVEs in this product scope (14 CVEs).

14 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
XStream is a Java library to serialize objects to XML and back again. In XStream before version 1.4.16, there is a vulnerability may allow a remote attacker to load and execute arb
Mar 23, 20219.182NOYES
XStream is a Java library to serialize objects to XML and back again. In XStream before version 1.4.16, there is a vulnerability which may allow a remote attacker who has sufficien
Mar 23, 20219.980NOYES
XStream is a Java library to serialize objects to XML and back again. In XStream before version 1.4.16, there is a vulnerability which may allow a remote attacker to load and execu
Mar 23, 20219.874NONO
XStream is a Java library to serialize objects to XML and back again. In XStream before version 1.4.16, there is a vulnerability which may allow a remote attacker to load and execu
Mar 23, 20219.873NONO
XStream is a Java library to serialize objects to XML and back again. In XStream before version 1.4.16, there is vulnerability which may allow a remote attacker to allocate 100% CP
Mar 23, 20217.568NONO
XStream is a Java library to serialize objects to XML and back again. In XStream before version 1.4.16, there is a vulnerability where the processed stream at unmarshalling time co
Mar 23, 20219.155NONO
XStream is a Java library to serialize objects to XML and back again. In XStream before version 1.4.16, there is a vulnerability which may allow a remote attacker to request data f
Mar 23, 20218.653NONO
XStream is a Java library to serialize objects to XML and back again. In XStream before version 1.4.16, there is a vulnerability where the processed stream at unmarshalling time co
Mar 23, 20217.550NONO
XStream is a Java library to serialize objects to XML and back again. In XStream before version 1.4.16, there is a vulnerability which may allow a remote attacker to execute arbitr
Mar 23, 20219.838NONO
XStream is a Java library to serialize objects to XML and back again. In XStream before version 1.4.16, there is a vulnerability which may allow a remote attacker to load and execu
Mar 23, 20219.837NONO

Exploit Exposure

Signals from CVEs in this product scope (14 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
2 CVEs
14.3% of CVEs· 97th percentile
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

Signals from CVEs in this product scope (14 CVEs).

Media Mentions

Signals from CVEs in this product scope (14 CVEs).

Top CNAs Publishing CVEs For Jmeter

Top CWEs

Versions

VersionCVE CountAvg CVSSAvg EPSSKEVExploits
5.019.82.7%00
4.019.82.7%00
3.329.86.8%00
3.229.86.8%00
3.129.86.8%00
3.029.86.8%00
2.929.86.8%00
2.829.86.8%00
2.729.86.8%00
2.629.86.8%00
2.5.129.86.8%00
2.529.86.8%00
2.429.86.8%00
2.3.429.86.8%00
2.3.329.86.8%00
2.3.229.86.8%00
2.3.129.86.8%00
2.329.86.8%00
2.229.86.8%00
2.1329.86.8%00