Impact
The vulnerability is an XML External Entity (XXE) flaw in the XML collector of OpenNMS Meridian and Horizon. When the collector parses XML that originates from an attacker-controlled source—such as a compromised monitored host or an HTTP man-in-the-middle position—the XML parser resolves external entities and external DTDs. This handling permits the reading of arbitrary files accessible to the OpenNMS service account, including sensitive database credentials, and can induce out-of-band network requests. The primary consequence is the disclosure of confidential data stored on the OpenNMS host.
Affected Systems
The flaw affects earlier releases of OpenNMS Meridian and Horizon prior to Meridian 2024.3.13 or 2025.0.10 and Horizon 36.0.4. Users of these legacy versions should consider upgrading to the specified mitigated releases. The vendor documentation notes that both products are designed for deployment inside organizational private networks and should not be exposed directly to the Internet.
Risk and Exploitability
With a CVSS score of 5.9, the vulnerability is classified as moderate severity. EPSS data is not available, and the flaw is not listed in the CISA KEV catalog. Exploitation requires that an attacker can supply or manipulate the XML source processed by the collector, which is typically achievable from compromised monitored hosts or via a network interception scenario. Consequently, the risk emerges mainly for environments where OpenNMS receives XML data from potentially untrusted endpoints. The impact is confined to information disclosure rather than remote code execution or system compromise.
OpenCVE Enrichment