Vulnerability index

Browse CVEs

24 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

MEDIUM 6.1 CVE-2023-40314 Cross-site scripting in bootstrap.jsp in multiple versions of OpenNMS Meridian and Horizon allows an attacker access to confidential session informat… Horizon 32.0.5 / 2023.1.9+ Fix from $1,6002023-11-16 HIGH 8.0 CVE-2023-40612 In OpenMNS Horizon 31.0.8 and versions earlier than 32.0.2, the file editor which is accessible to any user with ROLE_FILESYSTEM_EDITOR privileges is… Horizon 32.0.2 / 2023.1.5+ Fix from $1,9502023-08-23 HIGH 8.0 CVE-2023-40315 In OpenMNS Horizon 31.0.8 and versions earlier than 32.0.2 and related Meridian versions, any user that has the ROLE_FILESYSTEM_EDITOR can easily esc… Horizon 32.0.2 / 2023.1.5+ Fix from $1,9502023-08-17 HIGH 8.8 CVE-2023-40313 A BeanShell interpreter in remote server mode runs in OpenMNS Horizon versions earlier than 32.0.2 and in related Meridian versions which could allow… Horizon 32.0.2 / 2020.1.38+ Fix from $1,9502023-08-17 MEDIUM 5.2 CVE-2023-40312 Multiple reflected XSS were found on different JSP files with unsanitized parameters in OpenMNS Horizon 31.0.8 and versions earlier than 32.0.2 on mu… Horizon 32.0.2 / 2020.1.38+ Fix from $1,6002023-08-14 HIGH 8.0 CVE-2023-0872 The Horizon REST API includes a users endpoint in OpenMNS Horizon 31.0.8 and versions earlier than 32.0.2 on multiple platforms is vulnerable to elev… Horizon 32.0.2+ Fix from $1,9502023-08-14 MEDIUM 6.1 CVE-2023-0871 XXE injection in /rtc/post/ endpoint in OpenMNS Horizon 31.0.8 and versions earlier than 32.0.2 on multiple platforms is vulnerable to XML external e… Horizon 32.0.2 / 2020.1.38+ Fix from $1,6002023-08-11 MEDIUM 6.7 CVE-2023-0870 A form can be manipulated with cross-site request forgery in multiple versions of OpenNMS Meridian and Horizon. This can potentially allow an attacke… Horizon 31.0.6 / 2020.1.33+ Fix from $1,6002023-03-22 MEDIUM 6.1 CVE-2023-0867 Multiple stored and reflected cross-site scripting vulnerabilities in webapp jsp pages in multiple versions of OpenNMS Meridian and Horizon could all… Horizon 31.0.4 / 2023.1.0+ Fix from $1,6002023-02-23 MEDIUM 6.1 CVE-2023-0868 Reflected cross-site scripting in graph results in multiple versions of OpenNMS Meridian and Horizon could allow an attacker access to steal session … Horizon 31.0.4 / 2023.1.0+ Fix from $1,6002023-02-23 MEDIUM 6.1 CVE-2023-0869 Cross-site scripting in outage/list.htm in multiple versions of OpenNMS Meridian and Horizon allows an attacker access to confidential session inform… Horizon 31.0.4 / 2023.1.0+ Fix from $1,6002023-02-23 MEDIUM 6.5 CVE-2023-0815 Potential Insertion of Sensitive Information into Jetty Log Files in multiple versions of OpenNMS Meridian and Horizon could allow disclosure of user… Horizon 31.0.4 / 2023.1.0+ Fix from $1,6002023-02-23 MEDIUM 6.1 CVE-2023-0846 Unauthenticated, stored cross-site scripting in the display of alarm reduction keys in multiple versions of OpenNMS Horizon and Meridian could allow … Horizon 31.0.4 / 2023.1.0+ Fix from $1,6002023-02-22 MEDIUM 6.1 CVE-2016-6555 OpenNMS version 18.0.1 and prior are vulnerable to a stored XSS issue due to insufficient filtering of SNMP trap supplied data. By creating a malicio… Opennms 18.0.2-1+ Fix from $1,6002021-09-24 MEDIUM 6.1 CVE-2016-6556 OpenNMS version 18.0.1 and prior are vulnerable to a stored XSS issue due to insufficient filtering of SNMP agent supplied data. By creating a malici… Opennms 18.0.2-1+ Fix from $1,6002021-09-24 MEDIUM 5.4 CVE-2021-25932 In OpenNMS Horizon, versions opennms-1-0-stable through opennms-27.1.0-1; OpenNMS Meridian, versions meridian-foundation-2015.1.0-1 through meridian-… Meridian after 2020.1.6-1 Fix from $1,6002021-06-01 MEDIUM 5.4 CVE-2021-25934 In OpenNMS Horizon, versions opennms-18.0.0-1 through opennms-27.1.0-1; OpenNMS Meridian, versions meridian-foundation-2015.1.0-1 through meridian-fo… Horizon after 2020.1.7 Fix from $1,6002021-05-25 MEDIUM 5.4 CVE-2021-25935 In OpenNMS Horizon, versions opennms-17.0.0-1 through opennms-27.1.0-1; OpenNMS Meridian, versions meridian-foundation-2015.1.0-1 through meridian-fo… Horizon after 2020.1.7 Fix from $1,6002021-05-25 HIGH 8.8 CVE-2021-25931 In OpenNMS Horizon, versions opennms-1-0-stable through opennms-27.1.0-1; OpenNMS Meridian, versions meridian-foundation-2015.1.0-1 through meridian-… Horizon 27.1.1 / 2019.1.19+ Fix from $1,9502021-05-20 HIGH 8.8 CVE-2021-3396 OpenNMS Meridian 2016, 2017, 2018 before 2018.1.25, 2019 before 2019.1.16, and 2020 before 2020.1.5, Horizon 1.2 through 27.0.4, and Newts <1.5.3 has… Horizon 1.5.3 / 2018.1.25+ Fix from $1,9502021-02-17 CRITICAL 9.8 CVE-2020-1652 OpenNMS is accessible via port 9443 Opennms Mitigation only Fix from $2,3002020-07-17 HIGH 8.8 CVE-2020-12760 An issue was discovered in OpenNMS Horizon before 26.0.1, and Meridian before 2018.1.19 and 2019 before 2019.1.7. The ActiveMQ channel configuration … Opennms Horizon 26.1.0 / 2018.1.19+ Fix from $1,9502020-05-11 HIGH 8.1 CVE-2020-11886 OpenNMS Horizon and Meridian allows HQL Injection in element/nodeList.htm (aka the NodeListController) via snmpParm or snmpParmValue to addCriteriaFo… Horizon 25.2.1 / 2017.1.21+ Fix from $1,9502020-04-17 HIGH 10.0 CVE-2015-7856 OpenNMS has a default password of rtc for the rtc account, which makes it easier for remote attackers to obtain access by leveraging knowledge of the… Opennms Mitigation only Fix from $1,9502015-10-16