AlienVault OSSIM 'ws _ data' parameter SQL Injection Vulnerability
Release date:
Updated on:
Affected Systems:
AlienVault OSSIM
Description:
--------------------------------------------------------------------------------
Bugtraq id: 68996
CVE (CAN) ID: CVE-2014-5159
AlienVault OSSIM is an open-source security information and event management project.
A security vulnerability exists in the OSSIM-framework Service in versions earlier than AlienVault ossim 4.6.0. When the data provided by the user is used as part of an SQL query, parameter parameters of ws_data are not used for processing, attackers can exploit this vulnerability to execute SQL injection attacks in database context.
<* Source: grimmlin
Link: http://zerodayinitiative.com/advisories/ZDI-14-271/
*>
Suggestion:
--------------------------------------------------------------------------------
Vendor patch:
AlienVault
----------
The vendor has released a patch to fix this security problem. Please download it from the vendor's homepage:
Http://forums.alienvault.com/discussion/2559/security-advisory-multiple-vulnerabilities
This article permanently updates the link address: