The av-centerd SOAP service in AlienVault OSSIM before 4.8.0 allows remote attackers to read arbitrary files via a crafted get_file request.
| Software | From | Fixed in |
|---|---|---|
| alienvault / open_source_security_information_management | 4.3.3 | 4.3.3.x |
| alienvault / open_source_security_information_management | 4.5 | 4.5.x |
| alienvault / open_source_security_information_management | 4.0 | 4.0.x |
| alienvault / open_source_security_information_management | 4.4 | 4.4.x |
| alienvault / open_source_security_information_management | 4.6.1 | 4.6.1.x |
| alienvault / open_source_security_information_management | 4.6 | 4.6.x |
| alienvault / open_source_security_information_management | - | 4.7.0.x |