| dc.contributor.author | CĂCIULESCU, Alexandru Răzvan | |
| dc.contributor.author | BĂDĂNOIU, Matei | |
| dc.contributor.author | RUGHINIS, Răzvan | |
| dc.contributor.author | ŢURCANU, Dinu | |
| dc.date.accessioned | 2026-07-15T18:47:59Z | |
| dc.date.available | 2026-07-15T18:47:59Z | |
| dc.date.issued | 2026 | |
| dc.identifier.citation | CĂCIULESCU, Alexandru Răzvan; Matei BĂDĂNOIU; Răzvan RUGHINIS and Dinu ŢURCANU. Exploiting Jolokia for remote code execution: a cybersecurity analysis of CVE-2023-50780 in Apache ActiveMQ Artemis. Computers. 2026, vol. 15, nr. 6, art. nr. 367. ISSN 2073-431X. | en_US |
| dc.identifier.issn | 2073-431X | |
| dc.identifier.uri | https://www.doi.org/10.3390/computers15060367 | |
| dc.identifier.uri | https://repository.utm.md/handle/5014/36838 | |
| dc.description | Access full text: https://www.doi.org/10.3390/computers15060367 | en_US |
| dc.description.abstract | Java middleware platforms expose powerful management functions through HTTP-accessible interfaces such as Jolokia. This article discusses the analysis of CVE-2023-50780 in Apache ActiveMQ Artemis by framing the vulnerability as a management-plane state-transition problem rather than as a set of isolated exploit recipes. We analyze three remote-code-execution paths that combine Jolokia-accessible MBeans with Log4J2 configuration mutability, Artemis filesystem and deployment semantics, broker or web-server restart behavior, and, in one vector, the Java DiagnosticCommand interface. The study defines a formal attacker model; separates demonstrated preconditions from deployment-dependent assumptions; compares the three vectors across required privileges, network dependencies, writable artifacts, execution triggers, reliability, detection opportunities, and mitigations; and evaluates defensive controls at the level of the exploit stage they interrupt. The paper also clarifies the responsible-disclosure context and reduces operational payload detail in favor of defender-oriented evidence, validation tables, and architectural analysis. The resulting contribution is a reproducible but bounded case study of how legitimate administrative operations can compose into code execution when management interfaces are exposed without sufficient privilege separation, MBean restriction, filesystem hardening, and upgrade controls. | en_US |
| dc.language.iso | en | en_US |
| dc.publisher | Multidisciplinary Digital Publishing Institute (MDPI) | en_US |
| dc.rights | Attribution-NonCommercial-NoDerivs 3.0 United States | * |
| dc.rights.uri | http://creativecommons.org/licenses/by-nc-nd/3.0/us/ | * |
| dc.subject | management-plane security | en_US |
| dc.subject | vulnerability analysis | en_US |
| dc.subject | middleware security | en_US |
| dc.title | Exploiting Jolokia for remote code execution: a cybersecurity analysis of CVE-2023-50780 in Apache ActiveMQ Artemis | en_US |
| dc.type | Article | en_US |
The following license files are associated with this item: