Impact
A low‑privileged authenticated user can inject SQL by supplying a DATE_FORMAT parameter to the JasperReports‑based reporting REST API. The report templates use this value unescaped, allowing arbitrary SQL to be run against the OpenNMS database. As a result, an attacker can read confidential data, including provisioning credentials, notification secrets, and SNMP community strings, which is a direct breach of confidentiality.
Affected Systems
The vulnerability is found in multiple versions of The OpenNMS Group Horizon and Meridian. All builds prior to Horizon 36.0.4 and Meridian 2024.3.13 (or 2025.0.10) are affected. The manufacturers recommend upgrading to these or newer releases.
Risk and Exploitability
The CVSS score of 6.5 indicates moderate severity, and the vulnerability is not listed in CISA KEV. Exploitation requires authentication as a ROLE_USER. Based on the is exposed to the Internet or a trusted network, an attacker could abuse the REST API. The potential impact is significant data breach and credential compromise, making the risk noteworthy despite the lack of a public exploit. Monitoring for anomalous report execution and restricting network access mitigates the attack likelihood.
OpenCVE Enrichment