CVE-2016-8581: Alienvault Open Source Security Information And Event Management

Medium severity, CVSS 6.1. EPSS: 17.1% chance of exploitation in the next 30 days.

A persistent XSS vulnerability exists in the User-Agent header of the login process of AlienVault OSSIM and USM before 5.3.2 that allows an attacker to steal session IDs of logged in users when the current sessions are viewed by an administrator.

Affected products

  • Alienvault Open Source Security Information And Event Management: up to and including 5.3.1
  • Alienvault Unified Security Management: up to and including 5.3.1

Published 2016-10-28. Last modified 2026-06-17.