CRITICAL✓ PATCH🇵🇱 Wersja polska

CVE-2016-8582

CVSS 9.8v3.0pub. 2016-10-28upd. 2026-05-06

A vulnerability exists in gauge.php of AlienVault OSSIM and USM before 5.3.2 that allows an attacker to execute an arbitrary SQL query and retrieve database information or read local system files via MySQL's LOAD_FILE.

CVSS Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
  • Alienvault Open Source Security Information And Event Management

    APP
    Alienvault
    ≤ 5.3.1
  • Alienvault Unified Security Management

    APP
    Alienvault
    ≤ 5.3.1
🟢
PATCH AVAILABLE
Vendor update available. Deploy in standard maintenance cycle.
Tags
SQLi
CWE
References

Related vulnerabilities

CVE-2018-7279CRITICAL9.8PL ✓same product

RCE w AlienVault USM i OSSIM przed wersją 5.5.1

CVE-2017-6972CRITICAL9.8PL ✓same product

AlienVault USM/OSSIM i NfSen – błąd porzucania uprawnień, kod Perl uruchamiany jako root

CVE-2016-7955CRITICAL9.8PL ✓same product

Auth Bypass w AlienVault OSSIM/USM via nagłówka HTTP User-Agent

CVE-2016-8580CRITICAL9.8PL ✓same product

PHP Object Injection w AlienVault OSSIM/USM — zdalne wykonanie kodu

CVE-2017-6970HIGH8.4same product

AlienVault USM and OSSIM before 5.3.7 and NfSen before 1.3.8 allow local users to execute arbitrary commands i...