CVE-2019-12124: Onap Open Network Automation Platform
Critical severity, CVSS 9.1. EPSS: 1.2% chance of exploitation in the next 30 days.
An issue was discovered in ONAP APPC before Dublin. By using an exposed unprotected Jolokia interface, an unauthenticated attacker can read or overwrite an arbitrary file. All APPC setups are affected.
Affected products
- Onap Open Network Automation Platform: from 3.0.0, before 4.0.0 (fixed in 4.0.0)
Published 2020-03-18. Last modified 2026-06-17.