CVE-2019-12131: Onap Open Network Automation Platform
Critical severity, CVSS 9.1. EPSS: 1.2% chance of exploitation in the next 30 days.
An issue was detected in ONAP APPC through Dublin and SDC through Dublin. By setting a USER_ID parameter in an HTTP header, an attacker may impersonate an arbitrary existing user without any authentication. All APPC and SDC setups are affected.
Affected products
- Onap Open Network Automation Platform: from 3.0.0, before 4.0.0 (fixed in 4.0.0)
Published 2020-03-18. Last modified 2026-06-17.