CVE-2014-5383: SQL Injection
Published Aug 21, 2014
·Updated
SQL injection vulnerability in AlienVault OSSIM before 4.7.0 allows remote authenticated users to execute arbitrary SQL commands via unspecified vectors.
Affected Software
29 affected components
AlienVault Open Source Security Information Management<=4.6.1
AlienVault Open Source Security Information Management=1.0.4
AlienVault Open Source Security Information Management=1.0.6
AlienVault Open Source Security Information Management=2.1
AlienVault Open Source Security Information Management=2.1.2
AlienVault Open Source Security Information Management=2.1.5
AlienVault Open Source Security Information Management=2.1.5-1
AlienVault Open Source Security Information Management=2.1.5-2
AlienVault Open Source Security Information Management=2.1.5-3
AlienVault Open Source Security Information Management=3.1
AlienVault Open Source Security Information Management=3.1.9
AlienVault Open Source Security Information Management=3.1.10
AlienVault Open Source Security Information Management=3.1.12
AlienVault Open Source Security Information Management=4.0
AlienVault Open Source Security Information Management=4.0.3
AlienVault Open Source Security Information Management=4.0.4
AlienVault Open Source Security Information Management=4.1
AlienVault Open Source Security Information Management=4.1.2
AlienVault Open Source Security Information Management=4.1.3
AlienVault Open Source Security Information Management=4.2
AlienVault Open Source Security Information Management=4.2.2
AlienVault Open Source Security Information Management=4.2.3
AlienVault Open Source Security Information Management=4.3
AlienVault Open Source Security Information Management=4.3.1
AlienVault Open Source Security Information Management=4.3.2
AlienVault Open Source Security Information Management=4.3.3
AlienVault Open Source Security Information Management=4.4
AlienVault Open Source Security Information Management=4.5
AlienVault Open Source Security Information Management=4.6
Event History
Aug 21, 2014
CVE Published
via MITRE·02:00 PM
Data Sourced
via MITRE·02:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2014-5383?
CVE-2014-5383 has a medium severity due to the potential for remote authenticated users to execute arbitrary SQL commands.
2
How do I fix CVE-2014-5383?
To fix CVE-2014-5383, upgrade AlienVault OSSIM to version 4.7.0 or later.
3
What software is affected by CVE-2014-5383?
CVE-2014-5383 affects multiple versions of AlienVault OSSIM prior to 4.7.0.
4
Can CVE-2014-5383 be exploited remotely?
Yes, CVE-2014-5383 can be exploited by remote authenticated users.
5
What type of vulnerability is CVE-2014-5383?
CVE-2014-5383 is a SQL injection vulnerability.