Skip to content
Open access

From Logging Configuration to Code Execution: A Systematization of Log4j 2 File-Write Primitives in HTTP-Exposed JMX

Aug 2026 · Computers · 0 citations · 19 references

Abstract

Java middleware may expose Java Management Extensions (JMX) through Jolokia’s Hypertext Transfer Protocol (HTTP) bridge. In affected ActiveMQ deployments, reachable Log4j 2 configuration managed beans (MBeans) become write capabilities and, with compatible triggers, enable remote code execution (RCE). We ask: in a specified product/version state, which writes and triggers compose into RCE, and which operational guard first fails or remains unresolved? We synthesize two published case studies into an evidence-coded method. Four write and four trigger classes recover four observed chains, isolate one model-implied pairing, and reject dependency-level candidates through failed or unresolved guards. It distinguishes ActiveMQ paths from documentation-limited Apache James, WildFly, Apache Karaf, and Red Hat AMQ cases. Egress filtering and static-file ownership do not stop every observed chain. Observed (O), derived (D), and model-implied (H) labels separate findings from hypotheses. The contribution is a falsifiable, product- and version-scoped management-plane instrument, not a new attack-stage sequence.

Read PDF

We use cookies to run the site and, with your consent, for analytics and to show ads. See our Cookie Policy.