SQL Injection Flaw in OpenNMS Horizon and Meridian Applications
CVE-2025-53122

6.9MEDIUM

Key Information:

Vendor
CVE Published:
26 June 2025

What is CVE-2025-53122?

A vulnerability has been identified in OpenNMS Horizon and Meridian applications, allowing attackers to exploit improper neutralization of special elements used in SQL commands, leading to SQL Injection attacks. This risk emphasizes the importance of restricting application accessibility to private networks. Users are advised to upgrade to Meridian version 2024.2.6 or newer and Horizon version 33.16 or newer to mitigate potential risks.

Affected Version(s)

Horizon Windows 25.2.1 < 33.1.6, 33.1.7

Horizon Windows 33.0.8 < 33.1.6, 33.1.7

Meridian Windows 2024.1.0 < 2024.2.6, 2024.2.7

References

CVSS V4

Score:
6.9
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
None
Attack Vector:
Adjacent Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Fábio Tomé of DevoTeam
.
CVE-2025-53122 : SQL Injection Flaw in OpenNMS Horizon and Meridian Applications