CVE-2014-4153: Infoleak
Published Jun 18, 2014
·Updated
The av-centerd SOAP service in AlienVault OSSIM before 4.8.0 allows remote attackers to read arbitrary files via a crafted getfile request.
Affected Software
7 affected components
AlienVault Open Source Security Information Management<=4.7.0
AlienVault Open Source Security Information Management=4.0
AlienVault Open Source Security Information Management=4.3.3
AlienVault Open Source Security Information Management=4.4
AlienVault Open Source Security Information Management=4.5
AlienVault Open Source Security Information Management=4.6
AlienVault Open Source Security Information Management=4.6.1
Event History
Jun 18, 2014
CVE Published
via MITRE·07:00 PM
Data Sourced
via MITRE·07:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2014-4153?
CVE-2014-4153 has a moderate severity rating due to its potential for unauthorized file access.
2
How do I fix CVE-2014-4153?
To fix CVE-2014-4153, upgrade to AlienVault OSSIM version 4.8.0 or later.
3
Which versions of AlienVault OSSIM are affected by CVE-2014-4153?
CVE-2014-4153 affects AlienVault OSSIM versions 4.0 through 4.7.0.
4
What types of attacks can exploit CVE-2014-4153?
CVE-2014-4153 can be exploited by remote attackers to read arbitrary files on the server.
5
Is CVE-2014-4153 a risk for my AlienVault OSSIM deployment?
Yes, if you are using an affected version of AlienVault OSSIM, there is a risk due to this vulnerability.