PT-2017-9432 · Alienvault · Usm+1
Lappsec
+1
·
Publicado
2017-03-15
·
Atualizado
2018-10-09
·
CVE-2016-7955
CVSS v3.1
9.8
Crítica
| Vetor | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
AlienVault OSSIM versions prior to 5.3.1
USM versions prior to 5.3.1
Description
The issue allows remote attackers to bypass authentication, potentially obtaining sensitive information, modifying the application, or executing arbitrary code as root. This is achieved via a specific "AV Report Scheduler" HTTP User-Agent header.
Recommendations
For AlienVault OSSIM versions prior to 5.3.1, update to version 5.3.1 or later to resolve the issue.
For USM versions prior to 5.3.1, update to version 5.3.1 or later to resolve the issue.
As a temporary workaround, consider restricting access to the
logcheck function in session.inc until a patch is available.Correção
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Alienvault Ossim
Usm