OpenNMS Meridian 和 Horizon 的多个版本中,基于 JasperReports 的报告功能存在 SQL 注入漏洞。一个低权限的已认证用户(ROLE_USER)可以通过报告 REST API(POST /rest/reports/{id})运行系统默认启用且预置的在线报告“维护合同已过期”(AssetManagementMaintExpired)和“维护合同策略”(AssetManagementMaintStrategy)。攻击者可以提供一个 DATE_FORMAT 参数,而报告模板会将其原样、
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| The OpenNMS Group | Meridian | 2024.1.0 ~ 2024.3.13 | - |
|
| The OpenNMS Group | Horizon | 36.0.0 ~ 36.0.4 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-89054 | 8.2 HIGH | OpenNMS missing authorization on /api/v2 PATCH endpoints allows unauthenticated configurat |
| CVE-2026-19596 | 5.9 MEDIUM | OpenNMS XML collector XXE allows arbitrary file read from the OpenNMS host |
No comments yet