CVE-2014-3805

The av-centerd SOAP service in AlienVault OSSIM before 4.7.0 allows remote attackers to execute arbitrary commands via a crafted (1) get_license, (2) get_log_line, or (3) update_system/upgrade_pro_web request, a different vulnerability than CVE-2014-3804.
Code Injection
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
10 UNKNOWN
NETWORK
LOW
AV:N/AC:L/Au:N/C:C/I:C/A:C
mitreCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 97%
VendorProductVersion
alienvaultopen_source_security_information_management
𝑥
≤ 4.6.1
alienvaultopen_source_security_information_management
4.0
alienvaultopen_source_security_information_management
4.0.3
alienvaultopen_source_security_information_management
4.0.4
alienvaultopen_source_security_information_management
4.1
alienvaultopen_source_security_information_management
4.1.2
alienvaultopen_source_security_information_management
4.1.3
alienvaultopen_source_security_information_management
4.2
alienvaultopen_source_security_information_management
4.2.2
alienvaultopen_source_security_information_management
4.2.3
alienvaultopen_source_security_information_management
4.3
alienvaultopen_source_security_information_management
4.3.1
alienvaultopen_source_security_information_management
4.3.2
alienvaultopen_source_security_information_management
4.3.3
alienvaultopen_source_security_information_management
4.4
alienvaultopen_source_security_information_management
4.5
alienvaultopen_source_security_information_management
4.6
𝑥
= Vulnerable software versions