VendorsAlienVaultopen_source_security_information_managementany version
Vulnerabilities

AlienVault Open Source Security Information Management (OSSIM) any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

16CVEs
CVE-2014-3804
The av-centerd SOAP service in AlienVault OSSIM before 4.7.0 allows remote attackers to execute arbitrary commands via a crafted (1) update_system_info_debian_package, (2) ossec_task, (3) set_ossim_setup admin_ip, (4) sync_rserver, or (5) set_ossim_setup framework_ip request, a different vulnerability than CVE-2014-3805.
Published 2014-06-13 · Modified
10.02 PoCEPSS 0.724
CVE-2014-5210
The av-centerd SOAP service in AlienVault OSSIM before 4.7.0 allows remote attackers to execute arbitrary commands via a crafted (1) remote_task or (2) get_license request, a different vulnerability than CVE-2014-3804 and CVE-2014-3805.
Published 2014-08-21 · Modified
10.01 PoCEPSS 0.149
CVE-2014-3805
The av-centerd SOAP service in AlienVault OSSIM before 4.7.0 allows remote attackers to execute arbitrary commands via a crafted (1) get_license, (2) get_log_line, or (3) update_system/upgrade_pro_web request, a different vulnerability than CVE-2014-3804.
Published 2014-06-13 · Modified
10.02 PoCEPSS 0.131
CVE-2014-4151
The av-centerd SOAP service in AlienVault OSSIM before 4.8.0 allows remote attackers to create arbitrary files and execute arbitrary code via a crafted set_file request.
Published 2014-06-18 · Modified
10.0EPSS 0.073
CVE-2014-4152
The av-centerd SOAP service in AlienVault OSSIM before 4.8.0 allows remote attackers to execute arbitrary code via a crafted remote_task request, related to injecting an ssh public key.
Published 2014-06-18 · Modified
10.0EPSS 0.058
CVE-2014-5158
The (1) av-centerd SOAP service and (2) backup command in the ossim-framework service in AlienVault OSSIM before 4.6.0 allows remote attackers to execute arbitrary commands via unspecified vectors.
Published 2014-08-21 · Modified
10.0EPSS 0.037
CVE-2018-7279
A remote code execution issue was discovered in AlienVault USM and OSSIM before 5.5.1.
Published 2018-03-14 · Modified
9.8EPSS 0.024
CVE-2014-4153
The av-centerd SOAP service in AlienVault OSSIM before 4.8.0 allows remote attackers to read arbitrary files via a crafted get_file request.
Published 2014-06-18 · Modified
7.81 PoCEPSS 0.074
CVE-2013-6056
OSSIM before 4.3.3.1 has tele_compress.php path traversal vulnerability
Published 2020-01-27 · Modified
7.8EPSS 0.017
CVE-2013-5967
Multiple SQL injection vulnerabilities in AlienVault Open Source Security Information Management (OSSIM) 4.3 and earlier allow remote attackers to execute arbitrary SQL commands via the date_from parameter to (1) radar-iso27001-potential.php, (2) radar-iso27001-A12IS_acquisition-pot.php, (3) radar-iso27001-A11AccessControl-pot.php, (4) radar-iso27001-A10Com_OP_Mgnt-pot.php, or (5) radar-pci-potential.php in RadarReport/.
Published 2013-10-09 · Modified
7.51 PoCEPSS 0.190
CVE-2009-4374
Directory traversal vulnerability in repository/repository_attachment.php in AlienVault Open Source Security Information Management (OSSIM) 2.1.5, and possibly other versions before 2.1.5-4, allows remote attackers to upload files into arbitrary directories via a .. (dot dot) in the id_document parameter.
Published 2009-12-21 · Modified
7.5EPSS 0.016
CVE-2014-5159
SQL injection vulnerability in the ossim-framework service in AlienVault OSSIM before 4.6.0 allows remote attackers to execute arbitrary SQL commands via the ws_data parameter.
Published 2014-08-21 · Modified
7.5EPSS 0.013
CVE-2015-4046
The asset discovery scanner in AlienVault OSSIM before 5.0.1 allows remote authenticated users to execute arbitrary commands via the assets array parameter to netscan/do_scan.php.
Published 2017-05-23 · Modified
7.2EPSS 0.027
CVE-2015-4045
The sudoers file in the asset discovery scanner in AlienVault OSSIM before 5.0.1 allows local users to gain privileges via a crafted nmap script.
Published 2017-05-23 · Modified
7.2EPSS 0.005
CVE-2014-5383
SQL injection vulnerability in AlienVault OSSIM before 4.7.0 allows remote authenticated users to execute arbitrary SQL commands via unspecified vectors.
Published 2014-08-21 · Modified
6.51 PoCEPSS 0.212
CVE-2013-5300
Multiple cross-site scripting (XSS) vulnerabilities in AlienVault Open Source Security Information Management (OSSIM) before 4.3.0 allow remote attackers to inject arbitrary web script or HTML via the withoutmenu parameter to (1) vulnmeter/index.php or (2) vulnmeter/sched.php; the (3) section parameter to av_inventory/task_edit.php; the (4) profile parameter to nfsen/rrdgraph.php; or the (5) scan_server or (6) targets parameter to vulnmeter/simulate.php.
Published 2013-08-15 · Modified
4.3EPSS 0.018