CVE-2009-4372: Input Validation
AlienVault Open Source Security Information Management (OSSIM) 2.1.5, and possibly other versions before 2.1.5-4, allows remote attackers to execute arbitrary commands via shell metacharacters in the uniqueid parameter to (1) wcl.php, (2) storagegraphs.php, (3) storagegraphs2.php, (4) storagegraphs3.php, and (5) storagegraphs4.php in sem/.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2009-4372?
CVE-2009-4372 has been classified as a high severity vulnerability due to its potential for remote command execution.
How do I fix CVE-2009-4372?
To resolve CVE-2009-4372, update AlienVault Open Source Security Information Management to version 2.1.5-4 or later.
What types of attacks can CVE-2009-4372 facilitate?
CVE-2009-4372 can facilitate remote code execution attacks through manipulation of the uniqueid parameter.
Which versions of AlienVault OSSIM are affected by CVE-2009-4372?
CVE-2009-4372 affects AlienVault OSSIM versions 2.1.5-1, 2.1.5-2, and 2.1.5-3.
Is CVE-2009-4372 still a threat to current versions of OSSIM?
CVE-2009-4372 should no longer pose a threat if AlienVault OSSIM is updated to version 2.1.5-4 or newer.