VYPR

Opennms Horizon

by Opennms

Source repositories

CVEs (2)

  • CVE-2020-12760HigMay 11, 2020
    risk 0.50cvss 8.8epss 0.03

    An issue was discovered in OpenNMS Horizon before 26.0.1, and Meridian before 2018.1.19 and 2019 before 2019.1.7. The ActiveMQ channel configuration allowed for arbitrary deserialization of Java objects (aka ActiveMQ Minion payload deserialization), leading to remote code…

  • CVE-2026-19182MedAug 13, 2026
    risk 0.21cvss 4.3epss 0.00

    An incorrect authorization check in the v2 Alarm REST API in OpenNMS Meridian and Horizon allows a low-privileged authenticated user (ROLE_REST) to acknowledge, escalate, or clear alarms recorded as an arbitrary username, and, when also assigned ROLE_READONLY, to modify alarm…