Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

Grimmlin

#15530of 53,633
17.5Total CVSS
Vulnerabilities · 2
High
2
PT-2014-6306
10
2014-08-01
At&T Cybersecurity · Alienvault Ossim · CVE-2014-5158
**Name of the Vulnerable Software and Affected Versions** AlienVault OSSIM versions prior to 4.6.0 **Description** The issue allows remote attackers to execute arbitrary commands. This is possible through the av-centerd SOAP service and the backup command in the ossim-framework service. **Recommendations** For versions prior to 4.6.0, update to version 4.6.0 or later to resolve the issue. As a temporary workaround, consider restricting access to the av-centerd SOAP service and the backup command in the ossim-framework service until a patch is applied.
PT-2014-6307
7.5
2014-08-01
Alienvault · Alienvault Ossim · CVE-2014-5159
**Name of the Vulnerable Software and Affected Versions** AlienVault OSSIM versions prior to 4.6.0 **Description** The issue allows remote attackers to execute arbitrary SQL commands via the `ws data` parameter, potentially leading to remote code execution. **Recommendations** For versions prior to 4.6.0, update to version 4.6.0 or later to resolve the issue. As a temporary workaround, consider restricting access to the `ws data` parameter to minimize the risk of exploitation.