CVE-2016-6555: OpenNMS Stored XSS via SNMP Trap Alerts
Published Sep 24, 2021
·Updated
OpenNMS version 18.0.1 and prior are vulnerable to a stored XSS issue due to insufficient filtering of SNMP trap supplied data. By creating a malicious SNMP trap, an attacker can store an XSS payload which will trigger when a user of the web UI views the events list page. This issue was fixed in version 18.0.2, released on September 20, 2016.
Affected Software
1 affected component
OpenNMS OpenNMS<18.0.2-1
Remediation
Patch Available
Event History
Sep 24, 2021
CVE Published
09:15 PM
Jun 15, 2022
CVE Published
via MITRE·06:35 PM
Data Sourced
via MITRE·06:35 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the vulnerability ID for this issue?
The vulnerability ID for this issue is CVE-2016-6555.
2
What is the severity level of CVE-2016-6555?
CVE-2016-6555 has a severity level of high.
3
How does CVE-2016-6555 affect OpenNMS?
CVE-2016-6555 affects OpenNMS version 18.0.1 and prior.
4
What is the impact of CVE-2016-6555?
CVE-2016-6555 allows an attacker to store a malicious XSS payload that can be triggered when a user views the events list page on the web UI.
5
How can CVE-2016-6555 be mitigated?
To mitigate CVE-2016-6555, upgrade OpenNMS to version 18.0.2-1 or newer.