CVE-2015-4046: Command Injection
Published May 23, 2017
·Updated
The asset discovery scanner in AlienVault OSSIM before 5.0.1 allows remote authenticated users to execute arbitrary commands via the assets array parameter to netscan/doscan.php.
Affected Software
1 affected component
AlienVault Open Source Security Information Management<=5.0
Remediation
Patch Available
Event History
May 23, 2017
CVE Published
via MITRE·03:56 AM
Data Sourced
via MITRE·03:56 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2015-4046?
CVE-2015-4046 is rated as a high severity vulnerability allowing remote authenticated users to execute arbitrary commands.
2
How do I fix CVE-2015-4046?
To fix CVE-2015-4046, upgrade to AlienVault OSSIM version 5.0.1 or later.
3
What type of vulnerability is CVE-2015-4046?
CVE-2015-4046 is a remote command execution vulnerability.
4
Who is affected by CVE-2015-4046?
CVE-2015-4046 affects AlienVault OSSIM versions prior to 5.0.1.
5
How does CVE-2015-4046 impact the system?
CVE-2015-4046 can allow an attacker to execute arbitrary commands, potentially compromising system security.