CVE-2014-5159: SQL Injection
Published Aug 21, 2014
·Updated
SQL injection vulnerability in the ossim-framework service in AlienVault OSSIM before 4.6.0 allows remote attackers to execute arbitrary SQL commands via the wsdata parameter.
Affected Software
27 affected components
AlienVault Open Source Security Information Management<=4.5
AlienVault Open Source Security Information Management=1.0.4
AlienVault Open Source Security Information Management=1.0.6
AlienVault Open Source Security Information Management=2.1
AlienVault Open Source Security Information Management=2.1.2
AlienVault Open Source Security Information Management=2.1.5
AlienVault Open Source Security Information Management=2.1.5-1
AlienVault Open Source Security Information Management=2.1.5-2
AlienVault Open Source Security Information Management=2.1.5-3
AlienVault Open Source Security Information Management=3.1
AlienVault Open Source Security Information Management=3.1.9
AlienVault Open Source Security Information Management=3.1.10
AlienVault Open Source Security Information Management=3.1.12
AlienVault Open Source Security Information Management=4.0
AlienVault Open Source Security Information Management=4.0.3
AlienVault Open Source Security Information Management=4.0.4
AlienVault Open Source Security Information Management=4.1
AlienVault Open Source Security Information Management=4.1.2
AlienVault Open Source Security Information Management=4.1.3
AlienVault Open Source Security Information Management=4.2
AlienVault Open Source Security Information Management=4.2.2
AlienVault Open Source Security Information Management=4.2.3
AlienVault Open Source Security Information Management=4.3
AlienVault Open Source Security Information Management=4.3.1
AlienVault Open Source Security Information Management=4.3.2
AlienVault Open Source Security Information Management=4.3.3
AlienVault Open Source Security Information Management=4.4
Event History
Aug 21, 2014
CVE Published
via MITRE·02:00 PM
Data Sourced
via MITRE·02:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2014-5159?
CVE-2014-5159 has a CVSS score of 7.5, indicating it is a high severity vulnerability.
2
How do I fix CVE-2014-5159?
To mitigate CVE-2014-5159, upgrade to AlienVault OSSIM version 4.6.0 or later.
3
What type of vulnerability is CVE-2014-5159?
CVE-2014-5159 is an SQL injection vulnerability in the ossim-framework service.
4
Who is affected by CVE-2014-5159?
CVE-2014-5159 affects multiple versions of AlienVault OSSIM prior to version 4.6.0.
5
Can CVE-2014-5159 be exploited remotely?
Yes, CVE-2014-5159 can be exploited by remote attackers through the ws_data parameter.