#VU13826 Improper input validation in Cassandra - CVE-2018-8016
Published: July 12, 2018 / Updated: July 12, 2018
Cassandra
Apache Foundation
Description
The vulnerability allows a remote attacker to execute arbitrary Java code on the target system.
The vulnerability exists due to improper binding of an unauthenticated Java Management Extensions (JMX)/Remote Method Invocation (RMI) interface to all network interfaces. A remote unauthenticated attacker can access the JMX/RMI interface via Java APIs, load a specially crafted file that submits malicious input and execute arbitrary Java code on the system.
Successful exploitation of this vulnerability may result in complete compromise of vulnerable system.