Alienvault
Alienvault Open Source Security Information Management: vulnerabilidades y CVE
Alienvault Open Source Security Information Management tiene 22 vulnerabilidades publicadas, 0 de ellas en los últimos 12 meses. 1 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE22
Últimos 12 meses0
Críticas1
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2013-6056 | Alta (7.5) | 1.7% | — | 27 ene 2020 | OSSIM before 4.3.3.1 has tele_compress.php path traversal vulnerability |
| CVE-2018-7279 | Crítica (9.8) | 2.4% | — | 14 mar 2018 | A remote code execution issue was discovered in AlienVault USM and OSSIM before 5.5.1. |
| CVE-2015-4046 | Alta (7.2) | 2.7% | — | 23 may 2017 | The asset discovery scanner in AlienVault OSSIM before 5.0.1 allows remote authenticated users to execute arbitrary commands via the assets array parameter to netscan/do_scan.php. |
| CVE-2015-4045 | Media (6.7) | 0.51% | — | 23 may 2017 | The sudoers file in the asset discovery scanner in AlienVault OSSIM before 5.0.1 allows local users to gain privileges via a crafted nmap script. |
| CVE-2014-5383 | Media (6.5) | 21% | — | 21 ago 2014 | SQL injection vulnerability in AlienVault OSSIM before 4.7.0 allows remote authenticated users to execute arbitrary SQL commands via unspecified vectors. |
| CVE-2014-5210 | Alta (10) | 15% | — | 21 ago 2014 | The av-centerd SOAP service in AlienVault OSSIM before 4.7.0 allows remote attackers to execute arbitrary commands via a crafted (1) remote_task or (2) get_license request, a different vulnerability than CVE-2014-3804… |
| CVE-2014-5159 | Alta (7.5) | 1.3% | — | 21 ago 2014 | SQL injection vulnerability in the ossim-framework service in AlienVault OSSIM before 4.6.0 allows remote attackers to execute arbitrary SQL commands via the ws_data parameter. |
| CVE-2014-5158 | Alta (10) | 3.7% | — | 21 ago 2014 | The (1) av-centerd SOAP service and (2) backup command in the ossim-framework service in AlienVault OSSIM before 4.6.0 allows remote attackers to execute arbitrary commands via unspecified vectors. |
| CVE-2014-4153 | Alta (7.8) | 7.4% | — | 18 jun 2014 | The av-centerd SOAP service in AlienVault OSSIM before 4.8.0 allows remote attackers to read arbitrary files via a crafted get_file request. |
| CVE-2014-4152 | Alta (10) | 5.8% | — | 18 jun 2014 | The av-centerd SOAP service in AlienVault OSSIM before 4.8.0 allows remote attackers to execute arbitrary code via a crafted remote_task request, related to injecting an ssh public key. |
| CVE-2014-4151 | Alta (10) | 7.3% | — | 18 jun 2014 | The av-centerd SOAP service in AlienVault OSSIM before 4.8.0 allows remote attackers to create arbitrary files and execute arbitrary code via a crafted set_file request. |
| CVE-2014-3805 | Alta (10) | 13% | — | 13 jun 2014 | The av-centerd SOAP service in AlienVault OSSIM before 4.7.0 allows remote attackers to execute arbitrary commands via a crafted (1) get_license, (2) get_log_line, or (3) update_system/upgrade_pro_web request, a… |
| CVE-2014-3804 | Alta (10) | 72% | — | 13 jun 2014 | The av-centerd SOAP service in AlienVault OSSIM before 4.7.0 allows remote attackers to execute arbitrary commands via a crafted (1) update_system_info_debian_package, (2) ossec_task, (3) set_ossim_setup admin_ip, (4)… |
| CVE-2013-5967 | Alta (7.5) | 19% | — | 9 oct 2013 | Multiple SQL injection vulnerabilities in AlienVault Open Source Security Information Management (OSSIM) 4.3 and earlier allow remote attackers to execute arbitrary SQL commands via the date_from parameter to (1)… |
| CVE-2013-5321 | Alta (7.5) | 1.4% | — | 20 ago 2013 | Multiple SQL injection vulnerabilities in AlienVault Open Source Security Information Management (OSSIM) 4.1 allow remote attackers to execute arbitrary SQL commands via the (1) sensor parameter in a Query action to… |
| CVE-2013-5300 | Media (4.3) | 1.8% | — | 15 ago 2013 | Multiple cross-site scripting (XSS) vulnerabilities in AlienVault Open Source Security Information Management (OSSIM) before 4.3.0 allow remote attackers to inject arbitrary web script or HTML via the withoutmenu… |
| CVE-2012-3835 | Media (4.3) | 2.2% | — | 3 jul 2012 | Multiple cross-site scripting (XSS) vulnerabilities in AlienVault Open Source Security Information Management (OSSIM) 3.1 allow remote attackers to inject arbitrary web script or HTML via the (1) url parameter to… |
| CVE-2012-3834 | Media (6.5) | 1.4% | — | 3 jul 2012 | SQL injection vulnerability in forensics/base_qry_main.php in AlienVault Open Source Security Information Management (OSSIM) 3.1 allows remote authenticated users to execute arbitrary SQL commands via the time[0][0]… |
| CVE-2009-4375 | Alta (7.5) | 0.97% | — | 21 dic 2009 | SQL injection vulnerability in repository/repository_attachment.php in AlienVault Open Source Security Information Management (OSSIM) 2.1.5, and possibly other versions before 2.1.5-4, allows remote attackers to execute… |
| CVE-2009-4374 | Alta (7.5) | 1.6% | — | 21 dic 2009 | Directory traversal vulnerability in repository/repository_attachment.php in AlienVault Open Source Security Information Management (OSSIM) 2.1.5, and possibly other versions before 2.1.5-4, allows remote attackers to… |
| CVE-2009-4373 | Alta (7.5) | 3.0% | — | 21 dic 2009 | Unrestricted file upload vulnerability in repository/repository_attachment.php in AlienVault Open Source Security Information Management (OSSIM) 2.1.5, and possibly other versions before 2.1.5-4, allows remote attackers… |
| CVE-2009-4372 | Alta (7.5) | 4.8% | — | 21 dic 2009 | AlienVault Open Source Security Information Management (OSSIM) 2.1.5, and possibly other versions before 2.1.5-4, allows remote attackers to execute arbitrary commands via shell metacharacters in the uniqueid parameter… |