Vulnerability index

Browse CVEs

153 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Splunk MEDIUM 5.3
CVE-2024-36996

In Splunk Enterprise versions below 9.2.2, 9.1.5, and 9.0.10 and Splunk Cloud Platform versions below 9.1.2312.109, an attacker could determine wheth…

Fix: 9.1.5 / 9.1.2312.109+
Fix from $1,600 2024-07-01
Splunk HIGH 7.5
CVE-2024-36991EPSS 13%

In Splunk Enterprise on Windows versions below 9.2.2, 9.1.5, and 9.0.10, an attacker could perform a path traversal on the /modules/messaging/ endpoi…

Fix: 9.0.10 / 9.1.5+
Fix from $1,950 2024-07-01
Cloud MEDIUM 6.5
CVE-2024-36987

In Splunk Enterprise versions below 9.2.2, 9.1.5, and 9.0.10 and Splunk Cloud Platform versions below 9.1.2312.200, an authenticated, low-privileged …

Fix: 9.0.10 / 9.1.5+
Fix from $1,600 2024-07-01
Splunk MEDIUM 6.5
CVE-2024-36990

In Splunk Enterprise versions below 9.2.2, 9.1.5, and 9.0.10 and Splunk Cloud Platform versions below 9.2.2403.100, an authenticated, low-privileged …

Fix: 9.0.10 / 9.1.5+
Fix from $1,600 2024-07-01
Splunk HIGH 8.8
CVE-2024-36983

In Splunk Enterprise versions below 9.2.2, 9.1.5, and 9.0.10 and Splunk Cloud Platform versions below 9.1.2312.109 and 9.1.2308.207, an authenticated…

Fix: 9.0.10 / 9.1.5+
Fix from $1,950 2024-07-01
Splunk HIGH 8.8
CVE-2024-36984

In Splunk Enterprise versions below 9.2.2, 9.1.5, and 9.0.10 on Windows, an authenticated user could execute a specially crafted query that they coul…

Fix: 9.0.10 / 9.1.5+
Fix from $1,950 2024-07-01
Splunk HIGH 8.8
CVE-2024-36985EPSS 6%

In Splunk Enterprise versions below 9.2.2, 9.1.5, and 9.0.10, a low-privileged user that does not hold the admin or power Splunk roles could cause a …

Fix: 9.0.10 / 9.1.5+
Fix from $1,950 2024-07-01
Cloud HIGH 7.5
CVE-2024-36982

In Splunk Enterprise versions below 9.2.2, 9.1.5, and 9.0.10 and Splunk Cloud Platform versions below 9.1.2312.109 and 9.1.2308.207, an attacker coul…

Fix: 9.0.10 / 9.1.5+
Fix from $1,950 2024-07-01
Cloud MEDIUM 5.7
CVE-2024-36986

In Splunk Enterprise versions below 9.2.2, 9.1.5, and 9.0.10 and Splunk Cloud Platform versions below 9.1.2312.200 and 9.1.2308.207, an authenticated…

Fix: 9.0.10 / 9.1.5+
Fix from $1,600 2024-07-01
Splunk HIGH 8.1
CVE-2024-29946

In Splunk Enterprise versions below 9.2.1, 9.1.4, and 9.0.9, the Dashboard Examples Hub lacks protections for risky SPL commands. This could let atta…

Fix: 9.0.9 / 9.1.4+
Fix from $1,950 2024-03-27
Splunk HIGH 7.2
CVE-2024-29945

In Splunk Enterprise versions below 9.2.1, 9.1.4, and 9.0.9, the software potentially exposes authentication tokens during the token validation proce…

Fix: 9.0.9 / 9.1.4+
Fix from $1,950 2024-03-27
Add On Builder HIGH 7.2
CVE-2023-46231

In Splunk Add-on Builder versions below 4.1.4, the application writes user session tokens to its internal log files when you visit the Splunk Add-on …

Fix: 4.1.4+
Fix from $1,950 2024-01-30
Splunk HIGH 8.8
CVE-2024-23678

In Splunk Enterprise for Windows versions below 9.0.8 and 9.1.3, Splunk Enterprise does not correctly sanitize path input data. This results in the u…

Fix: 9.0.8 / 9.1.3+
Fix from $1,950 2024-01-22
Cloud MEDIUM 6.5
CVE-2024-23675

In Splunk Enterprise versions below 9.0.8 and 9.1.3, Splunk app key value store (KV Store) improperly handles permissions for users that use the REST…

Fix: 9.0.8 / 9.1.3+
Fix from $1,600 2024-01-22
Cloud MEDIUM 5.3
CVE-2024-23677

In Splunk Enterprise versions below 9.0.8, the Splunk RapidDiag utility discloses server responses from external applications in a log file.

Fix: 9.0.8 / 9.0.2208+
Fix from $1,600 2024-01-22
Enterprise Security MEDIUM 6.5
CVE-2024-22165

In Splunk Enterprise Security (ES) versions lower than 7.1.2, an attacker can create a malformed Investigation to perform a denial of service (DoS). …

Fix: 7.1.2+
Fix from $1,600 2024-01-09
Cloud HIGH 8.8
CVE-2023-46214EPSS 89%

In Splunk Enterprise versions below 9.0.7 and 9.1.2, Splunk Enterprise does not safely sanitize extensible stylesheet language transformations (XSLT)…

Fix: 9.0.7 / 9.1.2+
Fix from $1,950 2023-11-16
It Service Intelligence HIGH 8.6
CVE-2023-4571

In Splunk IT Service Intelligence (ITSI) versions below below 4.13.3, 4.15.3, or 4.17.1, a malicious actor can inject American National Standards Ins…

Fix: 4.13.3 / 4.15.3+
Fix from $1,950 2023-08-30
Splunk HIGH 8.8
CVE-2023-40595

In Splunk Enterprise versions lower than 8.2.12, 9.0.6, and 9.1.1, an attacker can execute a specially crafted query that they can then use to serial…

Fix: 8.2.12 / 9.0.6+
Fix from $1,950 2023-08-30
Splunk HIGH 8.8
CVE-2023-40596

In Splunk Enterprise versions earlier than 8.2.12, 9.0.6, and 9.1.1, a dynamic link library (DLL) that ships with Splunk Enterprise references an ins…

Fix: 8.2.12 / 9.0.6+
Fix from $1,950 2023-08-30
Splunk HIGH 8.8
CVE-2023-40597

In Splunk Enterprise versions lower than 8.2.12, 9.0.6, and 9.1.1, an attacker can exploit an absolute path traversal to execute arbitrary code that …

Fix: 8.2.12 / 9.0.6+
Fix from $1,950 2023-08-30
Splunk HIGH 8.8
CVE-2023-40598

In Splunk Enterprise versions below 8.2.12, 9.0.6, and 9.1.1, an attacker can create an external lookup that calls a legacy internal function. The at…

Fix: 8.2.12 / 9.0.6+
Fix from $1,950 2023-08-30
Splunk HIGH 7.5
CVE-2023-40593

In Splunk Enterprise versions lower than 9.0.6 and 8.2.12, a malicious actor can send a malformed security assertion markup language (SAML) request t…

Fix: 8.2.12 / 9.0.6+
Fix from $1,950 2023-08-30
Splunk HIGH 7.5
CVE-2023-40594

In Splunk Enterprise versions lower than 8.2.12, 9.0.6, and 9.1.1, an attacker can use the `printf` SPL function to perform a denial of service (DoS)…

Fix: 8.2.12 / 9.0.6+
Fix from $1,950 2023-08-30
Splunk MEDIUM 6.1
CVE-2023-40592

In Splunk Enterprise versions below 9.1.1, 9.0.6, and 8.2.12, an attacker can craft a special web request that can result in reflected cross-site scr…

Fix: 8.2.12 / 9.0.6+
Fix from $1,600 2023-08-30
Soar HIGH 7.8
CVE-2023-3997

Splunk SOAR versions lower than 6.1.0 are indirectly affected by a potential vulnerability accessed through the user’s terminal. A third party can se…

Fix: 6.1.0 / 6.1.0.131+
Fix from $1,950 2023-07-31
Splunk App For Stream CRITICAL 9.9
CVE-2023-32713

In Splunk App for Stream versions below 8.1.1, a low-privileged user could use a vulnerability in the streamfwd process within the Splunk App for Str…

Fix: 8.1.1+
Fix from $2,300 2023-06-01
Splunk HIGH 8.8
CVE-2023-32707EPSS 79%

In versions of Splunk Enterprise below 9.0.5, 8.2.11, and 8.1.14, and Splunk Cloud Platform below version 9.0.2303.100, a low-privileged user who hol…

Fix: 8.1.14 / 8.2.11+
Fix from $1,950 2023-06-01
Splunk HIGH 8.8
CVE-2023-32708

In Splunk Enterprise versions below 9.0.5, 8.2.11, and 8.1.14, and Splunk Cloud Platform versions below 9.0.2303.100, a low-privileged user can trigg…

Fix: 8.1.14 / 8.2.11+
Fix from $1,950 2023-06-01
Splunk HIGH 8.1
CVE-2023-32714EPSS 43%

In the Splunk App for Lookup File Editing versions below 4.0.1, a low-privileged user can, with a specially crafted web request, trigger a path trave…

Fix: 4.0.1 / 8.1.14+
Fix from $1,950 2023-06-01