CVE-2014-3805: Code Injection
Published Jun 13, 2014
·Updated
The av-centerd SOAP service in AlienVault OSSIM before 4.7.0 allows remote attackers to execute arbitrary commands via a crafted (1) getlicense, (2) getlogline, or (3) updatesystem/upgradeproweb request, a different vulnerability than CVE-2014-3804.
Affected Software
17 affected components
AlienVault Open Source Security Information Management<=4.6.1
AlienVault Open Source Security Information Management=4.0
AlienVault Open Source Security Information Management=4.0.3
AlienVault Open Source Security Information Management=4.0.4
AlienVault Open Source Security Information Management=4.1
AlienVault Open Source Security Information Management=4.1.2
AlienVault Open Source Security Information Management=4.1.3
AlienVault Open Source Security Information Management=4.2
AlienVault Open Source Security Information Management=4.2.2
AlienVault Open Source Security Information Management=4.2.3
AlienVault Open Source Security Information Management=4.3
AlienVault Open Source Security Information Management=4.3.1
AlienVault Open Source Security Information Management=4.3.2
AlienVault Open Source Security Information Management=4.3.3
AlienVault Open Source Security Information Management=4.4
AlienVault Open Source Security Information Management=4.5
AlienVault Open Source Security Information Management=4.6
Event History
Jun 13, 2014
CVE Published
via MITRE·02:00 PM
Data Sourced
via MITRE·02:00 PM
Description
Data Sourced
via NVD·02:55 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2014-3805?
CVE-2014-3805 is classified as a high-severity vulnerability that allows remote attackers to execute arbitrary commands on affected systems.
2
How do I fix CVE-2014-3805?
To mitigate CVE-2014-3805, upgrade AlienVault OSSIM to version 4.7.0 or later.
3
Which versions of AlienVault OSSIM are affected by CVE-2014-3805?
CVE-2014-3805 affects AlienVault OSSIM versions up to and including 4.6.1.
4
What type of attacks does CVE-2014-3805 enable?
CVE-2014-3805 enables remote attackers to execute arbitrary commands via crafted SOAP service requests.
5
Is CVE-2014-3805 related to any other vulnerabilities?
Yes, CVE-2014-3805 is related to CVE-2014-3804 but describes a different type of vulnerability.