CVE-2016-8582: Alienvault Open Source Security Information And Event Management

Critical severity, CVSS 9.8. EPSS: 57.4% chance of exploitation in the next 30 days.

A vulnerability exists in gauge.php of AlienVault OSSIM and USM before 5.3.2 that allows an attacker to execute an arbitrary SQL query and retrieve database information or read local system files via MySQL's LOAD_FILE.

Affected products

  • Alienvault Open Source Security Information And Event Management: up to and including 5.3.1
  • Alienvault Unified Security Management: up to and including 5.3.1

Published 2016-10-28. Last modified 2026-06-17.