Total vulnerabilities in the database
OpenNMS Horizon and Meridian allows HQL Injection in element/nodeList.htm (aka the NodeListController) via snmpParm or snmpParmValue to addCriteriaForSnmpParm. This affects Horizon before 25.2.1, Meridian 2019 before 2019.1.4, Meridian 2018 before 2018.1.16, and Meridian 2017 before 2017.1.21.
Software | From | Fixed in |
---|---|---|
opennms / horizon | - | 25.2.1 |
opennms / meridian | 2017 | 2017.1.21 |
opennms / meridian | 2018 | 2018.1.16 |
opennms / meridian | 2019 | 2019.1.4 |