The av-centerd SOAP service in AlienVault OSSIM before 4.7.0 allows remote attackers to execute arbitrary commands via a crafted (1) remote_task or (2) get_license request, a different vulnerability than CVE-2014-3804 and CVE-2014-3805.
The product constructs all or part of a code segment using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the syntax or behavior of the intended code segment.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Open_source_security_information_management | Alienvault | * | 4.6.1 (including) |
Open_source_security_information_management | Alienvault | 1.0.4 (including) | 1.0.4 (including) |
Open_source_security_information_management | Alienvault | 1.0.6 (including) | 1.0.6 (including) |
Open_source_security_information_management | Alienvault | 2.1 (including) | 2.1 (including) |
Open_source_security_information_management | Alienvault | 2.1.2 (including) | 2.1.2 (including) |
Open_source_security_information_management | Alienvault | 2.1.5 (including) | 2.1.5 (including) |
Open_source_security_information_management | Alienvault | 2.1.5-1 (including) | 2.1.5-1 (including) |
Open_source_security_information_management | Alienvault | 2.1.5-2 (including) | 2.1.5-2 (including) |
Open_source_security_information_management | Alienvault | 2.1.5-3 (including) | 2.1.5-3 (including) |
Open_source_security_information_management | Alienvault | 3.1 (including) | 3.1 (including) |
Open_source_security_information_management | Alienvault | 3.1.9 (including) | 3.1.9 (including) |
Open_source_security_information_management | Alienvault | 3.1.10 (including) | 3.1.10 (including) |
Open_source_security_information_management | Alienvault | 3.1.12 (including) | 3.1.12 (including) |
Open_source_security_information_management | Alienvault | 4.0 (including) | 4.0 (including) |
Open_source_security_information_management | Alienvault | 4.0.3 (including) | 4.0.3 (including) |
Open_source_security_information_management | Alienvault | 4.0.4 (including) | 4.0.4 (including) |
Open_source_security_information_management | Alienvault | 4.1 (including) | 4.1 (including) |
Open_source_security_information_management | Alienvault | 4.1.2 (including) | 4.1.2 (including) |
Open_source_security_information_management | Alienvault | 4.1.3 (including) | 4.1.3 (including) |
Open_source_security_information_management | Alienvault | 4.2 (including) | 4.2 (including) |
Open_source_security_information_management | Alienvault | 4.2.2 (including) | 4.2.2 (including) |
Open_source_security_information_management | Alienvault | 4.2.3 (including) | 4.2.3 (including) |
Open_source_security_information_management | Alienvault | 4.3 (including) | 4.3 (including) |
Open_source_security_information_management | Alienvault | 4.3.1 (including) | 4.3.1 (including) |
Open_source_security_information_management | Alienvault | 4.3.2 (including) | 4.3.2 (including) |
Open_source_security_information_management | Alienvault | 4.3.3 (including) | 4.3.3 (including) |
Open_source_security_information_management | Alienvault | 4.4 (including) | 4.4 (including) |
Open_source_security_information_management | Alienvault | 4.5 (including) | 4.5 (including) |
Open_source_security_information_management | Alienvault | 4.6 (including) | 4.6 (including) |