简体   繁体   English

替代SNMP4J(发送陷阱)

[英]Alternate to SNMP4J(sending traps)

Currently, i am using SNMP4J in my java project for sending Traps(v1,v2, and v3), But when I tried to check for security vulnerabilities using NIST dependency checker tool which uses NVD(national vulnerability Database), I found out that there are some security vulnerabilities. 当前,我在Java项目中使用SNMP4J发送陷阱(v1,v2和v3),但是当我尝试使用使用NVD(国家漏洞数据库)的NIST依赖项检查器工具检查安全漏洞时,我发现那里一些安全漏洞。

Can anyone suggest some alternate library for sending traps? 谁能建议一些替代库来发送陷阱?
在此处输入图片说明

That report includes false alarms only. 该报告仅包含错误警报。 If you read the details you will recognise that all the issues refer to older NET-SNMP implementations or at least implementations not related to SNMP4J. 如果阅读详细信息,您将认识到所有问题都涉及较旧的NET-SNMP实施,或者至少涉及与SNMP4J不相关的实施。 SNMP4J has no relationship and no dependency to these implementations. SNMP4J与这些实现没有关系,也没有依赖性。

Thus you can simply ignore that report or ask the authors to improve their report quality. 因此,您可以简单地忽略该报告或要求作者提高其报告质量。 It seems that they are simply searching for the keyword "SNMP" in package names which is very poor "analysis". 看来他们只是在软件包名称中搜索关键字“ SNMP”,而这是非常糟糕的“分析”。

声明:本站的技术帖子网页,遵循CC BY-SA 4.0协议,如果您需要转载,请注明本站网址或者原文地址。任何问题请咨询:yoyou2525@163.com.

 
粤ICP备18138465号  © 2020-2024 STACKOOM.COM