Check Point Reference: | CPAI-2014-1832 |
Date Published: | 22 Oct 2014 |
Severity: | Critical |
Last Updated: | Wednesday 22 October, 2014 |
Source: | AlienVault |
Industry Reference: | CVE-2014-5210 |
Protection Provided by: |
Security Gateway |
Who is Vulnerable? | AlienVault AlienVault prior to 4.7.0 |
Vulnerability Description | An arbitrary command execution vulnerability has been reported in AlienVault OSSIM. The vulnerability is due to failure to safely sanitize remote_task SOAP requests within Util.pm. This vulnerability can be exploit by sending crafted requests to the affected service. |
SmartView Tracker will log the following entries:
Attack Name: Application Servers Protection Violation.
Attack Information: AlienVault OSSIM av-centerd Util.pm remote_task Arbitrary Command Execution