Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Jolokia

First CVE: Oct 6, 2014Active for: 12 yearsTotal CVEs: 4

Jolokia is a niche Java management and monitoring agent that provides remote JMX access and introspection capabilities, with exposure centered on its core agent product and webarchive deployments. The observed vulnerabilities cluster around web-layer input handling and cross-site concerns, including CSRF, input validation bypasses, cross-site scripting, and injection flaws that reflect the agent's HTTP interface and request-processing role. Current severity, exploitation, and exposure counts are shown alongside this summary.

FAUCET AI Generated
4
Total CVEs
More Total CVEs than 79% of tracked vendors
0.7
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 10% of tracked vendors
7.5
Avg CVSS Score
Higher Avg CVSS Score than 56% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Jolokia over time

Volume of CVEsAvg CVSS Base Score
First CVE
Oct 6, 2014
11 years ago
Most Recent CVE
Aug 1, 2019
2,549 days ago

Products(2 total)

Top CVEs

Signals from CVEs in this vendor scope (4 CVEs).

4 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2018-1000130HIGH
A JNDI Injection vulnerability exists in Jolokia agent version 1.3.7 in the proxy mode that allows a remote attacker to run arbitrary Java code on the server.
Mar 14, 20188.175NOYES
CVE-2018-1000129MEDIUM
An XSS vulnerability exists in the Jolokia agent version 1.3.7 in the HTTP servlet that allows an attacker to execute malicious javascript in the victim's browser.
Mar 14, 20186.144NOYES
CVE-2018-10899HIGH
A flaw was found in Jolokia versions from 1.2 to before 1.6.1. Affected versions are vulnerable to a system-wide CSRF. This holds true for properly configured instances with strict
Aug 1, 20198.828NONO
CVE-2014-0168MEDIUM
Cross-site request forgery (CSRF) vulnerability in Jolokia before 1.2.1 allows remote attackers to hijack the authentication of users for requests that execute MBeans methods via a
Oct 6, 20146.822NONO
View all 4 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products4 CVEs
50%
50%
Severity distribution among all CVEs352,294 CVEs
45%
40%
11%
MediumHigh
Attack Vector
Local0 (0.0%)
Network3 (75.0%)
Unknown1 (25.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low2 (50.0%)
High1 (25.0%)
Unknown1 (25.0%)
User Interaction
None1 (25.0%)
Unknown1 (25.0%)
Required2 (50.0%)
Privileges Required
Low0 (0.0%)
High0 (0.0%)
None3 (75.0%)
Unknown1 (25.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (4 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
2 CVEs
50.0% of CVEs· 98th percentile
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Jolokia.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Jolokia — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Jolokia's Products

View all 2 CNAs →

Top CWEs