PT-2020-9278 · Onap · Onap Operations Manager+1

Published

2020-03-18

·

Updated

2021-07-21

·

CVE-2019-12114

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions ONAP HOLMES versions prior to Dublin ONAP Operations Manager (OOM) (affected versions not specified)
Description An issue was discovered in ONAP HOLMES. By accessing port 9202 of the dep-holmes-engine-mgmt pod, an unauthenticated attacker who already has access to pod-to-pod communication may execute arbitrary code inside that pod.
Recommendations For ONAP HOLMES versions prior to Dublin, consider restricting access to port 9202 of the dep-holmes-engine-mgmt pod to minimize the risk of exploitation. For ONAP Operations Manager (OOM), at the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Missing Authentication

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2019-12114

Affected Products

Onap Holmes
Onap Operations Manager