Vulnerabilities (CVE)

Filtered by vendor Opennms Subscribe
Filtered by product Horizon
Total 22 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2021-3396 1 Opennms 3 Horizon, Meridian, Newts 2023-12-10 6.5 MEDIUM 8.8 HIGH
OpenNMS Meridian 2016, 2017, 2018 before 2018.1.25, 2019 before 2019.1.16, and 2020 before 2020.1.5, Horizon 1.2 through 27.0.4, and Newts <1.5.3 has Incorrect Access Control, which allows local and remote code execution using JEXL expressions.
CVE-2020-11886 1 Opennms 2 Horizon, Meridian 2023-12-10 5.5 MEDIUM 8.1 HIGH
OpenNMS Horizon and Meridian allows HQL Injection in element/nodeList.htm (aka the NodeListController) via snmpParm or snmpParmValue to addCriteriaForSnmpParm. This affects Horizon before 25.2.1, Meridian 2019 before 2019.1.4, Meridian 2018 before 2018.1.16, and Meridian 2017 before 2017.1.21.