PHP object injection vulnerabilities exist in multiple widget files in AlienVault OSSIM and USM before 5.3.2. These vulnerabilities allow arbitrary PHP code execution via magic methods in included classes.
| Software | From | Fixed in |
|---|---|---|
| alienvault / unified_security_management | - | 5.3.1.x |
| alienvault / open_source_security_information_and_event_management | - | 5.3.1.x |