CVE-2009-3441

OSSIM < 2.1.2 - Unauthenticated Authentication Bypass via Direct Request

Title source: llm
STIX 2.1

Description

Open Source Security Information Management (OSSIM) before 2.1.2 allows remote attackers to bypass authentication, and read graphs or infrastructure information, via a direct request to (1) graphs/alarms_events.php or (2) host/draw_tree.php.

References (4)

Core 4
Core References
Exploit vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/36504
Vendor Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/36867
Third Party Advisory, VDB Entry mailing-list x_refsource_bugtraq
http://www.securityfocus.com/archive/1/506663/100/0/threaded

Scores

EPSS 0.0229
EPSS Percentile 81.0%

Details

CWE
CWE-287
Status published
Products (3)
alienvault/ossim 1.0.4
alienvault/ossim 1.0.6
alienvault/ossim < 2.1
Published Sep 28, 2009
Tracked Since Feb 18, 2026