PHP object injection vulnerabilities exist in multiple widget files in AlienVault OSSIM and USM before 5.3.2. These vulnerabilities allow arbitrary PHP code execution via magic methods in included classes.
CVSS Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HAlienvault Open Source Security Information And Event Management
APPAlienvault≤ 5.3.1Alienvault Unified Security Management
APPAlienvault≤ 5.3.1
🟢
PATCH AVAILABLE
Vendor update available. Deploy in standard maintenance cycle.
Tags
RCE
CWE
Related vulnerabilities
CVE-2018-7279CRITICAL9.8PL ✓same product
RCE w AlienVault USM i OSSIM przed wersją 5.5.1
CVE-2017-6972CRITICAL9.8PL ✓same product
AlienVault USM/OSSIM i NfSen – błąd porzucania uprawnień, kod Perl uruchamiany jako root
CVE-2016-7955CRITICAL9.8PL ✓same product
Auth Bypass w AlienVault OSSIM/USM via nagłówka HTTP User-Agent
CVE-2016-8582CRITICAL9.8PL ✓same product
SQL Injection w AlienVault OSSIM/USM — plik gauge.php
CVE-2017-6970HIGH8.4same product
AlienVault USM and OSSIM before 5.3.7 and NfSen before 1.3.8 allow local users to execute arbitrary commands i...