Reputation: 469
Currently, i am using SNMP4J in my java project for sending Traps(v1,v2, and v3), But when I tried to check for security vulnerabilities using NIST dependency checker tool which uses NVD(national vulnerability Database), I found out that there are some security vulnerabilities.
Can anyone suggest some alternate library for sending traps?
Upvotes: 0
Views: 334
Reputation: 377
That report includes false alarms only. If you read the details you will recognise that all the issues refer to older NET-SNMP implementations or at least implementations not related to SNMP4J. SNMP4J has no relationship and no dependency to these implementations.
Thus you can simply ignore that report or ask the authors to improve their report quality. It seems that they are simply searching for the keyword "SNMP" in package names which is very poor "analysis".
Upvotes: 2