Vulnerability index

Browse CVEs

21 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Open Network Automation Platform CRITICAL 9.8
CVE-2019-12125

In ONAP Logging through Dublin, by accessing an applicable port (30234, 30290, 32010, 30270, 30224, 30281, 30254, 30285, and/or 30271), an attacker g…

Fix: 4.0.0+
Fix from $2,300 2020-03-19
Open Network Automation Platform CRITICAL 9.8
CVE-2019-12126

In ONAP DCAE through Dublin, by accessing an applicable port (30234, 30290, 32010, 30270, 30224, 30281, 30254, 30285, and/or 30271), an attacker gain…

Fix: 4.0.0+
Fix from $2,300 2020-03-19
Open Network Automation Platform CRITICAL 9.8
CVE-2019-12127

In ONAP OOM through Dublin, by accessing an applicable port (30234, 30290, 32010, 30270, 30224, 30281, 30254, 30285, and/or 30271), an attacker gains…

Fix: 4.0.0+
Fix from $2,300 2020-03-19
Open Network Automation Platform CRITICAL 9.8
CVE-2019-12128

In ONAP SO through Dublin, by accessing an applicable port (30234, 30290, 32010, 30270, 30224, 30281, 30254, 30285, and/or 30271), an attacker gains …

Fix: after 4.0.0
Fix from $2,300 2020-03-19
Open Network Automation Platform CRITICAL 9.8
CVE-2019-12129

In ONAP MSB through Dublin, by accessing an applicable port (30234, 30290, 32010, 30270, 30224, 30281, 30254, 30285, and/or 30271), an attacker gains…

Fix: after 4.0.0
Fix from $2,300 2020-03-19
Open Network Automation Platform CRITICAL 9.8
CVE-2019-12130

In ONAP CLI through Dublin, by accessing an applicable port (30234, 30290, 32010, 30270, 30224, 30281, 30254, 30285, and/or 30271), an attacker gains…

Fix: after 4.0.0
Fix from $2,300 2020-03-19
Open Network Automation Platform CRITICAL 9.8
CVE-2019-12132

An issue was discovered in ONAP SDNC before Dublin. By executing sla/dgUpload with a crafted filename parameter, an unauthenticated attacker can exec…

Fix: 4.0.0+
Fix from $2,300 2020-03-18
Open Network Automation Platform CRITICAL 9.8
CVE-2019-12112

An issue was discovered in ONAP SDNC before Dublin. By executing sla/upload with a crafted filename parameter, an unauthenticated attacker can execut…

Fix: 4.0.0+
Fix from $2,300 2020-03-18
Open Network Automation Platform CRITICAL 9.8
CVE-2019-12114

An issue was discovered in ONAP HOLMES before Dublin. By accessing port 9202 of dep-holmes-engine-mgmt pod, an unauthenticated attacker (who already …

Fix: 4.0.0+
Fix from $2,300 2020-03-18
Open Network Automation Platform CRITICAL 9.8
CVE-2019-12115

An issue was discovered in ONAP SDC through Dublin. By accessing port 4000 of demo-sdc-sdc-be pod, an unauthenticated attacker (who already has acces…

Fix: 4.0.0+
Fix from $2,300 2020-03-18
Open Network Automation Platform CRITICAL 9.8
CVE-2019-12116

An issue was discovered in ONAP SDC through Dublin. By accessing port 6000 of demo-sdc-sdc-fe pod, an unauthenticated attacker (who already has acces…

Fix: 4.0.0+
Fix from $2,300 2020-03-18
Open Network Automation Platform CRITICAL 9.8
CVE-2019-12117

An issue was discovered in ONAP SDC through Dublin. By accessing port 4001 of demo-sdc-sdc-onboarding-be pod, an unauthenticated attacker (who alread…

Fix: 4.0.0+
Fix from $2,300 2020-03-18
Open Network Automation Platform CRITICAL 9.8
CVE-2019-12118

An issue was discovered in ONAP SDC through Dublin. By accessing port 7001 of demo-sdc-sdc-wfd-be pod, an unauthenticated attacker (who already has a…

Fix: 4.0.0+
Fix from $2,300 2020-03-18
Open Network Automation Platform CRITICAL 9.8
CVE-2019-12119

An issue was discovered in ONAP SDC through Dublin. By accessing port 7000 of demo-sdc-sdc-wfd-fe pod, an unauthenticated attacker (who already has a…

Fix: 4.0.0+
Fix from $2,300 2020-03-18
Open Network Automation Platform CRITICAL 9.8
CVE-2019-12120

An issue was discovered in ONAP VNFSDK through Dublin. By accessing port 8000 of demo-vnfsdk-vnfsdk, an unauthenticated attacker (who already has acc…

Fix: 4.0.0+
Fix from $2,300 2020-03-18
Open Network Automation Platform CRITICAL 9.1
CVE-2019-12124

An issue was discovered in ONAP APPC before Dublin. By using an exposed unprotected Jolokia interface, an unauthenticated attacker can read or overwr…

Fix: 4.0.0+
Fix from $2,300 2020-03-18
Open Network Automation Platform CRITICAL 9.1
CVE-2019-12131

An issue was detected in ONAP APPC through Dublin and SDC through Dublin. By setting a USER_ID parameter in an HTTP header, an attacker may impersona…

Fix: 4.0.0+
Fix from $2,300 2020-03-18
Open Network Automation Platform HIGH 8.8
CVE-2019-12113

An issue was discovered in ONAP SDNC before Dublin. By executing sla/printAsGv with a crafted module parameter, an authenticated user can execute an …

Fix: 4.0.0+
Fix from $1,950 2020-03-18
Open Network Automation Platform HIGH 8.8
CVE-2019-12123

An issue was discovered in ONAP SDNC before Dublin. By executing sla/printAsXml with a crafted module parameter, an authenticated user can execute an…

Fix: 4.0.0+
Fix from $1,950 2020-03-18
Open Network Automation Platform HIGH 7.5
CVE-2019-12121

An issue was detected in ONAP Portal through Dublin. By executing a padding oracle attack using the ONAPPORTAL/processSingleSignOn UserId field, an a…

Fix: 4.0.0+
Fix from $1,950 2020-03-18
Open Network Automation Platform MEDIUM 6.5
CVE-2019-12122

An issue was discovered in ONAP Portal through Dublin. By executing a call to ONAPPORTAL/portalApi/loggedinUser, an attacker who possesses a user's c…

Fix: 4.0.0+
Fix from $1,600 2020-03-18