IRTUM – Institutional Repository of the Technical University of Moldova

Exploiting Jolokia for remote code execution: a cybersecurity analysis of CVE-2023-50780 in Apache ActiveMQ Artemis

Show simple item record

dc.contributor.author CĂCIULESCU, Alexandru Răzvan
dc.contributor.author BĂDĂNOIU, Matei
dc.contributor.author RUGHINIS, Răzvan
dc.contributor.author ŢURCANU, Dinu
dc.date.accessioned 2026-07-15T18:47:59Z
dc.date.available 2026-07-15T18:47:59Z
dc.date.issued 2026
dc.identifier.citation CĂCIULESCU, Alexandru Răzvan; Matei BĂDĂNOIU; Răzvan RUGHINIS and Dinu ŢURCANU. Exploiting Jolokia for remote code execution: a cybersecurity analysis of CVE-2023-50780 in Apache ActiveMQ Artemis. Computers. 2026, vol. 15, nr. 6, art. nr. 367. ISSN 2073-431X. en_US
dc.identifier.issn 2073-431X
dc.identifier.uri https://www.doi.org/10.3390/computers15060367
dc.identifier.uri https://repository.utm.md/handle/5014/36838
dc.description Access full text: https://www.doi.org/10.3390/computers15060367 en_US
dc.description.abstract Java middleware platforms expose powerful management functions through HTTP-accessible interfaces such as Jolokia. This article discusses the analysis of CVE-2023-50780 in Apache ActiveMQ Artemis by framing the vulnerability as a management-plane state-transition problem rather than as a set of isolated exploit recipes. We analyze three remote-code-execution paths that combine Jolokia-accessible MBeans with Log4J2 configuration mutability, Artemis filesystem and deployment semantics, broker or web-server restart behavior, and, in one vector, the Java DiagnosticCommand interface. The study defines a formal attacker model; separates demonstrated preconditions from deployment-dependent assumptions; compares the three vectors across required privileges, network dependencies, writable artifacts, execution triggers, reliability, detection opportunities, and mitigations; and evaluates defensive controls at the level of the exploit stage they interrupt. The paper also clarifies the responsible-disclosure context and reduces operational payload detail in favor of defender-oriented evidence, validation tables, and architectural analysis. The resulting contribution is a reproducible but bounded case study of how legitimate administrative operations can compose into code execution when management interfaces are exposed without sufficient privilege separation, MBean restriction, filesystem hardening, and upgrade controls. en_US
dc.language.iso en en_US
dc.publisher Multidisciplinary Digital Publishing Institute (MDPI) en_US
dc.rights Attribution-NonCommercial-NoDerivs 3.0 United States *
dc.rights.uri http://creativecommons.org/licenses/by-nc-nd/3.0/us/ *
dc.subject management-plane security en_US
dc.subject vulnerability analysis en_US
dc.subject middleware security en_US
dc.title Exploiting Jolokia for remote code execution: a cybersecurity analysis of CVE-2023-50780 in Apache ActiveMQ Artemis en_US
dc.type Article en_US


Files in this item

The following license files are associated with this item:

This item appears in the following Collection(s)

Show simple item record

Attribution-NonCommercial-NoDerivs 3.0 United States Except where otherwise noted, this item's license is described as Attribution-NonCommercial-NoDerivs 3.0 United States

Search DSpace


Browse

My Account