7.8
CVSSv3

CVE-2021-37942

Published: 22/11/2023 Updated: 30/11/2023
CVSS v3 Base Score: 7.8 | Impact Score: 5.9 | Exploitability Score: 1.8
VMScore: 0

Vulnerability Summary

A local privilege escalation issue was found with the APM Java agent, where a user on the system could attach a malicious plugin to an application running the APM Java agent. By using this vulnerability, an attacker could execute code at a potentially higher level of permissions than their user typically has access to.

Vulnerable Product Search on Vulmon Subscribe to Product

elastic apm java agent