Re: [opennms-devel] OpenNMS vulnerability discussed in Java blog post

2015-11-10 Thread Ronny Trommer
FYI: This is the apache commons statement regarding this issue: http://markmail.org/message/l3cu5ughkm3abbth?q=list:org%2Eapache%2Eannounce/ > On 10.11.2015, at 15:41, Ronny Trommer wrote: > > Hi Michael, > > We sent information about this issue to opennms-announce mailing list and > first in

Re: [opennms-devel] OpenNMS vulnerability discussed in Java blog post

2015-11-10 Thread Ronny Trommer
Hi Michael, We sent information about this issue to opennms-announce mailing list and first information addressing this issues can be find here: http://www.adventuresinoss.com/2015/11/09/opennms-rmi-exploit/ http://www.opennms.eu/

[opennms-devel] OpenNMS vulnerability discussed in Java blog post

2015-11-07 Thread Michael Banck
Hi, probably you heard about it already, but I noticed OpenNMS (through RMI, not sure how relevant that is these days) was mentioned in this article: http://foxglovesecurity.com/2015/11/06/what-do-weblogic-websphere-jboss-jenkins-opennms-and-your-application-have-in-common-this-vulnerability/#ope