VYPR
High severity7.5NVD Advisory· Published Jun 20, 2018· Updated Jun 17, 2026

CVE-2018-1132

CVE-2018-1132

Description

A flaw was found in Opendaylight's SDNInterfaceapp (SDNI). Attackers can SQL inject the component's database (SQLite) without authenticating to the controller or SDNInterfaceapp. SDNInterface has been deprecated in OpenDayLight since it was last used in the final Carbon series release. In addition to the component not being included in OpenDayLight in newer releases, the SDNInterface component is not packaged in the opendaylight package included in RHEL.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

3
  • Opendaylight/Sdninterfaceappinferred3 versions
    (expand)+ 2 more
    • (no CPE)
    • cpe:2.3:a:opendaylight:sdninterfaceapp:*:*:*:*:*:*:*:*range: <=carbon-sr4
    • (no CPE)

Patches

Vulnerability mechanics

References

4

News mentions

0

No linked articles in our index yet.