Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
MAL-010 — MAL-010: Dangerous MBeans Accessible via JMX in Apache James | Kitploit
Tools/GitHubGitHub/mbadanoiu/mal-010
Privilege EscalationVulnerability AnalysisExploitationPenetration TestingRed Teaming
GitHubmbadanoiu/mal-010

MAL-010

MAL-010: Dangerous MBeans Accessible via JMX in Apache James

View Repository
1 year agoNot yet reviewed

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

MAL-010: Dangerous MBeans Accessible via JMX in Apache James

By listing and inspecting the MBeans exposed by the JMX on localhost, port 9999, the following attack vectors have been identified:

  • Arbitrary File Write using Log4J
  • Arbitrary File Read using Log4J

Note: Unlike the “MLet attack” presented in CVE-2023-26269, this vulnerability also works if authentication is required, if the attacker knows the JMX credentials.

Vendor Disclosure:

This vulnerability represents an alternative attack vector for CVE-2023-26269, therefore the vendor's disclosure and fix for this vulnerability can be found here.

Proof Of Concept:

More details and the exploitation process can be found in this PDF.

Additional Resources:

CVE-2023-26269: Misconfigured JMX in Apache James

Download Tool