多个版本的 OpenNMS Meridian 和 Horizon 中的 XML 采集器存在 XML 外部实体(XXE)漏洞。当 OpenNMS 从攻击者可控制的来源(例如已被攻陷的被监控主机,或处于 HTTP 中间人攻击位置的来源)采集 XML 时,采集器的 XML 解析器会解析外部实体和外部 DTD。这使得攻击者能够读取 OpenNMS 服务账户可访问的文件(包括数据库凭证),并触发带外(out-of-band)请求。 解决方案是升级至 Meridian 2024.3.13、2025.0.10 或更新版本,以及
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| The OpenNMS Group | Meridian | 2024.1.0 ~ 2024.3.13 | - |
|
| The OpenNMS Group | Horizon | 36.0.0 ~ 36.0.4 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-89054 | 8.2 HIGH | OpenNMS missing authorization on /api/v2 PATCH endpoints allows unauthenticated configurat |
| CVE-2026-89089 | 6.5 MEDIUM | OpenNMS SQL injection in shipped Asset Management JasperReports via the DATE_FORMAT parame |
No comments yet