CVE-2025-53122: SQLi in OpenNMS Horizon and Meridian
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in OpenNMS Horizon and Meridian applications allows SQL Injection.
Users should upgrade to Meridian 2024.2.6 or newer, or Horizon 33.16 or newer. Meridian and Horizon installation instructions state that they are intended for installation within an organization's private networks and should not be directly accessible from the Internet.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2025-53122?
CVE-2025-53122 is categorized as a critical vulnerability due to its potential to allow SQL injection attacks.
How do I fix CVE-2025-53122?
To remediate CVE-2025-53122, upgrade to Meridian version 2024.2.6 or newer, or Horizon version 33.16 or newer.
What applications are affected by CVE-2025-53122?
CVE-2025-53122 affects OpenNMS Meridian versions below 2024.2.6 and OpenNMS Horizon versions below 33.16.
What types of vulnerabilities can occur with CVE-2025-53122?
CVE-2025-53122 allows for SQL injection attacks, enabling unauthorized access to the database.
Is there a public exploit available for CVE-2025-53122?
As of now, there are no widely reported public exploits specifically for CVE-2025-53122, but the risk is significant.