SCA: security update for org.jolokia:jolokia-service-jsr160 (GHSA-c9ff-59g8-m36q)

high Tenable Cloud Security Plugin ID 473725

Description

There are packages installed that are affected by a vulnerability referenced in the following CVE:

- A flaw was found in Jolokia's JSR-160 proxy functionality where insufficient validation of client-
controlled JMX service URLs allows a bypass of the denylist introduced to mitigate CVE-2018-1000130. The
proxy accepts a `target.url` value from a Jolokia POST request and passes it to `JMXServiceURL` and
`JMXConnectorFactory` for establishing the remote JMX connection. The existing denylist only rejects URLs
matching `service:jmx:rmi:///jndi/ldap:.*`, which can be bypassed using alternative valid JMX service URL
forms, including `ldaps://` schemes or LDAP URLs with a non-empty JMX host component. These URLs are
accepted as valid `JMXServiceURL` objects and can cause the Jolokia agent JVM to perform a JNDI lookup
against an attacker-controlled LDAP endpoint. This can result in server-side request forgery (SSRF),
forwarding of supplied JMX credentials to the remote endpoint, and potentially remote code execution
depending on the classes and configuration available in the target JVM. (CVE-2026-84218)

Solution

Update the org.jolokia:jolokia-service-jsr160 library and its related packages to version 2.6.2 or later.

See Also

https://github.com/advisories/GHSA-c9ff-59g8-m36q

Plugin Details

Severity: High

ID: 473725

Version: Revision 1.1

Type: Local

Family: SCA Checks

Published: 10/7/2026

Updated: 10/7/2026

Risk Information

VPR

Risk Factor: Medium

Score: 4.9

Percentile: 58.17

Vendor

Vendor Severity: High

CVSS v2

Risk Factor: High

Base Score: 7.6

Temporal Score: 5.6

Vector: CVSS2#AV:N/AC:H/Au:N/C:C/I:C/A:C

CVSS Score Source: CVE-2026-84218

CVSS v3

Risk Factor: High

Base Score: 8.1

Temporal Score: 7.1

Vector: CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

Vulnerability Information

Exploit Ease: No known exploits are available

Patch Publication Date: 9/1/2026

Vulnerability Publication Date: 9/1/2026

Reference Information

CVE: CVE-2026-84218

cwe: CWE-184