9.8
CVSSv3

CVE-2016-7955

Published: 15/03/2017 Updated: 09/10/2018
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
CVSS v3 Base Score: 9.8 | Impact Score: 5.9 | Exploitability Score: 3.9
VMScore: 668
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

The logcheck function in session.inc in AlienVault OSSIM prior to 5.3.1, when an action has been created, and USM prior to 5.3.1 allows remote malicious users to bypass authentication and consequently obtain sensitive information, modify the application, or execute arbitrary code as root via an "AV Report Scheduler" HTTP User-Agent header.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

alienvault unified security management

alienvault ossim

Exploits

Alienvault OSSIM / USM versions 530 and below suffer from an authentication bypass vulnerability ...