The logcheck function in session.inc in AlienVault OSSIM before 5.3.1, when an action has been created, and USM before 5.3.1 allows remote attackers to bypass authentication and consequently obtain sensitive information, modify the application, or execute arbitrary code as root via an "AV Report Scheduler" HTTP User-Agent header.
CVSS Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HAlienvault Ossim
APPAlienvault≤ 5.3Alienvault Unified Security Management
APPAlienvault≤ 5.3
🟢
PATCH AVAILABLE
Vendor update available. Deploy in standard maintenance cycle.
Tags
RCEAuth Bypass
CWE
References
Related vulnerabilities
CVE-2018-7279CRITICAL9.8PL ✓same product
RCE w AlienVault USM i OSSIM przed wersją 5.5.1
CVE-2017-6972CRITICAL9.8PL ✓same product
AlienVault USM/OSSIM i NfSen – błąd porzucania uprawnień, kod Perl uruchamiany jako root
CVE-2016-8582CRITICAL9.8PL ✓same product
SQL Injection w AlienVault OSSIM/USM — plik gauge.php
CVE-2016-8580CRITICAL9.8PL ✓same product
PHP Object Injection w AlienVault OSSIM/USM — zdalne wykonanie kodu
CVE-2017-6970HIGH8.4same product
AlienVault USM and OSSIM before 5.3.7 and NfSen before 1.3.8 allow local users to execute arbitrary commands i...