Java JMX Server Insecure Configuration Java Code Execution

This Metasploit module takes advantage a Java JMX interface insecure configuration, which would allow loading classes from any remote (HTTP) URL. JMX interfaces with authentication disabled ( should be vulnerable, while interfaces with authentication enabled will be vulnerable only if a weak configuration is deployed (allowing to use, having a security manager allowing to load a ClassLoader MBean, etc.).

Leave a Reply