CVE-2014-5159: Alienvault Open Source Security Information Management
High severity, CVSS 7.5. EPSS: 1.3% chance of exploitation in the next 30 days.
SQL injection vulnerability in the ossim-framework service in AlienVault OSSIM before 4.6.0 allows remote attackers to execute arbitrary SQL commands via the ws_data parameter.
Affected products
- Alienvault Open Source Security Information Management: up to and including 4.5; version 1.0.4 only; version 1.0.6 only; version 2.1 only; version 2.1.2 only; version 2.1.5 only; …
Published 2014-08-21. Last modified 2026-06-17.