Lucene search

K
zdiHP Zero Day InitiativeZDI-14-207
HistoryJun 13, 2014 - 12:00 a.m.

AlienVault OSSIM av-centerd Util.pm get_file Information Disclosure Vulnerability

2014-06-1300:00:00
HP Zero Day Initiative
www.zerodayinitiative.com
16

EPSS

0.301

Percentile

97.0%

This vulnerability allows remote attackers to obtain sensitive information on vulnerable installations of AlienVault OSSIM. Authentication is not required to exploit this vulnerability. The specific flaw exists within the av-centerd SOAP service. The issue lies within the improper handling of a parameter in get_file requests. An attacker can leverage this vulnerability to read arbitrary files from the underlying OS with root privileges.

EPSS

0.301

Percentile

97.0%