OpenNMS User Credentials Information Disclosure Vulnerability
BID:67052
Info
OpenNMS User Credentials Information Disclosure Vulnerability
| Bugtraq ID: | 67052 |
| Class: | Design Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Apr 16 2014 12:00AM |
| Updated: | Apr 16 2014 12:00AM |
| Credit: | Michael Batz |
| Vulnerable: |
OpenNMS OpenNMS 1.9.93 OpenNMS OpenNMS 1.9.0 OpenNMS OpenNMS 1.12.5 OpenNMS OpenNMS 1.11.0 OpenNMS OpenNMS 1.10.3 OpenNMS OpenNMS 1.10.0 |
| Not Vulnerable: |
OpenNMS OpenNMS 1.13.1 OpenNMS OpenNMS 1.12.6 |
Discussion
OpenNMS User Credentials Information Disclosure Vulnerability
OpenNMS is prone to an information-disclosure vulnerability.
An attacker can exploit this issue to gain access to sensitive information; this may lead to further attacks.
Versions prior to OpenNMS 1.12.6 are vulnerable.
OpenNMS is prone to an information-disclosure vulnerability.
An attacker can exploit this issue to gain access to sensitive information; this may lead to further attacks.
Versions prior to OpenNMS 1.12.6 are vulnerable.
Exploit / POC
OpenNMS User Credentials Information Disclosure Vulnerability
Attackers can use a browser to exploit this issue.
Attackers can use a browser to exploit this issue.
Solution / Fix
OpenNMS User Credentials Information Disclosure Vulnerability
Solution:
Updates are available. Please see the references or vendor advisory for more information.
Solution:
Updates are available. Please see the references or vendor advisory for more information.
References
OpenNMS User Credentials Information Disclosure Vulnerability
References:
References:
- Cumulative Release History 1.12.6 (OpenNMS)
- OpenNMS HomePage (OpenNMS)
- REST API - Access to list of all user with non admin rights (OpenNMS)