Show filters
22 Total Results
Displaying 11-20 of 22
Sort by:
Attacker Value
Unknown
CVE-2019-12123
Disclosure Date: March 18, 2020 (last updated February 21, 2025)
An issue was discovered in ONAP SDNC before Dublin. By executing sla/printAsXml with a crafted module parameter, an authenticated user can execute an arbitrary command. All SDC setups that include admportal are affected.
0
Attacker Value
Unknown
CVE-2019-12114
Disclosure Date: March 18, 2020 (last updated February 21, 2025)
An issue was discovered in ONAP HOLMES before Dublin. By accessing port 9202 of dep-holmes-engine-mgmt pod, an unauthenticated attacker (who already has access to pod-to-pod communication) may execute arbitrary code inside that pod. All ONAP Operations Manager (OOM) setups are affected.
0
Attacker Value
Unknown
CVE-2019-12121
Disclosure Date: March 18, 2020 (last updated February 21, 2025)
An issue was detected in ONAP Portal through Dublin. By executing a padding oracle attack using the ONAPPORTAL/processSingleSignOn UserId field, an attacker is able to decrypt arbitrary information encrypted with the same symmetric key as UserId. All Portal setups are affected.
0
Attacker Value
Unknown
CVE-2019-12117
Disclosure Date: March 18, 2020 (last updated February 21, 2025)
An issue was discovered in ONAP SDC through Dublin. By accessing port 4001 of demo-sdc-sdc-onboarding-be pod, an unauthenticated attacker (who already has access to pod-to-pod communication) may execute arbitrary code inside that pod. All ONAP Operations Manager (OOM) setups are affected.
0
Attacker Value
Unknown
CVE-2019-12112
Disclosure Date: March 18, 2020 (last updated February 21, 2025)
An issue was discovered in ONAP SDNC before Dublin. By executing sla/upload with a crafted filename parameter, an unauthenticated attacker can execute an arbitrary command. All SDC setups that include admportal are affected.
0
Attacker Value
Unknown
CVE-2019-12120
Disclosure Date: March 18, 2020 (last updated February 21, 2025)
An issue was discovered in ONAP VNFSDK through Dublin. By accessing port 8000 of demo-vnfsdk-vnfsdk, an unauthenticated attacker (who already has access to pod-to-pod communication) may execute arbitrary code inside that pod. All ONAP Operations Manager (OOM) setups are affected.
0
Attacker Value
Unknown
CVE-2019-12115
Disclosure Date: March 18, 2020 (last updated February 21, 2025)
An issue was discovered in ONAP SDC through Dublin. By accessing port 4000 of demo-sdc-sdc-be pod, an unauthenticated attacker (who already has access to pod-to-pod communication) may execute arbitrary code inside that pod. All ONAP Operations Manager (OOM) setups are affected.
0
Attacker Value
Unknown
CVE-2019-12113
Disclosure Date: March 18, 2020 (last updated February 21, 2025)
An issue was discovered in ONAP SDNC before Dublin. By executing sla/printAsGv with a crafted module parameter, an authenticated user can execute an arbitrary command. All SDC setups that include admportal are affected.
0
Attacker Value
Unknown
CVE-2019-12122
Disclosure Date: March 18, 2020 (last updated February 21, 2025)
An issue was discovered in ONAP Portal through Dublin. By executing a call to ONAPPORTAL/portalApi/loggedinUser, an attacker who possesses a user's cookie may retrieve that user's password from the database. All Portal setups are affected.
0
Attacker Value
Unknown
CVE-2019-12124
Disclosure Date: March 18, 2020 (last updated November 27, 2024)
An issue was discovered in ONAP APPC before Dublin. By using an exposed unprotected Jolokia interface, an unauthenticated attacker can read or overwrite an arbitrary file. All APPC setups are affected.
0