opennms
Security Risk Profile
Security Risk Score
Comprehensive risk assessment based on 36 vulnerabilities, EPSS scores, exploitation status, and remediation availability.
📅 Data spans from February 9, 2009 to present
Threat Assessment
Severity Distribution
Exploit Likelihood
Age Distribution
Common Weaknesses (CWE)
Most Affected Products
Recent Vulnerabilities
See more →OpenNMS SQL injection in shipped Asset Management JasperReports via the DATE_FORMAT parameter (ROLE_USER)
OpenNMS XML collector XXE allows arbitrary file read from the OpenNMS host
OpenNMS missing authorization on /api/v2 PATCH endpoints allows unauthenticated configuration changes
OpenNMS v2 Alarm REST API inverted authorization check lets ROLE_REST users acknowledge alarms as any user and bypass read-only
OpenNMS JEXL sandbox bypass in Measurements REST API allows ROLE_USER to load arbitrary classes
SQLi in OpenNMS Horizon and Meridian
Cross-site scripting in bootstrap.jsp
Authenticated XXE Injection Via The File Editor
ROLE_FILESYSTEM_EDITOR Can Be Used To Escalate To ROLE_ADMIN
Disable BeanShell Interpreter Remote Server Mode
Monitor opennms in Real-Time
Get instant alerts when new vulnerabilities are discovered. Stay ahead of security threats with SecAlerts.