Vulnerability index

Browse CVEs

153 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Splunk MEDIUM 6.5
CVE-2023-32706

On Splunk Enterprise versions below 9.0.5, 8.2.11, and 8.1.14, an unauthenticated attacker can send specially-crafted messages to the XML parser with…

Fix: 8.1.14 / 8.2.11+
Fix from $1,600 2023-06-01
Splunk MEDIUM 6.5
CVE-2023-32716

In Splunk Enterprise versions below 9.0.5, 8.2.11, and 8.1.14, and Splunk Cloud Platform versions below 9.0.2303.100, an attacker can exploit a vulne…

Fix: 8.1.14 / 8.2.11+
Fix from $1,600 2023-06-01
Splunk App For Lookup File Editing MEDIUM 6.1
CVE-2023-32715

In the Splunk App for Lookup File Editing versions below 4.0.1, a user can insert potentially malicious JavaScript code into the app, which causes th…

Fix: 4.0.1+
Fix from $1,600 2023-06-01
Splunk MEDIUM 5.4
CVE-2023-32711

In Splunk Enterprise versions below 9.0.5, 8.2.11, and 8.1.14, a Splunk dashboard view lets a low-privileged user exploit a vulnerability in the Boot…

Fix: 8.1.14 / 8.2.11+
Fix from $1,600 2023-06-01
Splunk MEDIUM 5.3
CVE-2023-32710

In Splunk Enterprise versions below 9.0.5, 8.2.11, and 8.1.14, and in Splunk Cloud Platform versions below 9.0.2303.100, a low-privileged user can pe…

Fix: 8.1.14 / 8.2.11+
Fix from $1,600 2023-06-01
Splunk HIGH 8.8
CVE-2023-22935

In Splunk Enterprise versions below 8.1.13, 8.2.10, and 9.0.4, the ‘display.page.search.patterns.sensitivity’ search parameter lets a search bypass S…

Fix: 8.1.13 / 8.2.10+
Fix from $1,950 2023-02-14
Splunk HIGH 8.8
CVE-2023-22939

In Splunk Enterprise versions below 8.1.13, 8.2.10, and 9.0.4, the ‘map’ search processing language (SPL) command lets a search bypass SPL safeguards…

Fix: 8.1.13 / 8.2.10+
Fix from $1,950 2023-02-14
Splunk HIGH 8.0
CVE-2023-22934

In Splunk Enterprise versions below 8.1.13, 8.2.10, and 9.0.4, the ‘pivot’ search processing language (SPL) command lets a search bypass SPL safeguar…

Fix: 8.1.13 / 8.2.10+
Fix from $1,950 2023-02-14
Splunk HIGH 7.5
CVE-2023-22941

In Splunk Enterprise versions below 8.1.13, 8.2.10, and 9.0.4, an improperly-formatted ‘INGEST_EVAL’ parameter in a Field Transformation crashes the …

Fix: 8.1.13 / 8.2.10+
Fix from $1,950 2023-02-14
Splunk MEDIUM 6.3
CVE-2023-22936

In Splunk Enterprise versions below 8.1.13, 8.2.10, and 9.0.4, the ‘search_listener’ parameter in a search allows for a blind server-side request for…

Fix: 8.1.13 / 8.2.10+
Fix from $1,600 2023-02-14
Splunk MEDIUM 6.1
CVE-2023-22932

In Splunk Enterprise 9.0 versions before 9.0.4, a View allows for Cross-Site Scripting (XSS) through the error message in a Base64-encoded image. The…

Fix: 9.0.4 / 9.0.2209.3+
Fix from $1,600 2023-02-14
Splunk MEDIUM 6.1
CVE-2023-22933

In Splunk Enterprise versions below 8.1.13, 8.2.10, and 9.0.4, a View allows for Cross-Site Scripting (XSS) in an extensible mark-up language (XML) V…

Fix: 8.1.13 / 8.2.10+
Fix from $1,600 2023-02-14
Splunk MEDIUM 5.7
CVE-2023-22940

In Splunk Enterprise versions below 8.1.13, 8.2.10, and 9.0.4, aliases of the ‘collect’ search processing language (SPL) command, including ‘summaryi…

Fix: 8.1.13 / 8.2.10+
Fix from $1,600 2023-02-14
Add On Builder MEDIUM 5.3
CVE-2023-22943

In Splunk Add-on Builder (AoB) versions below 4.1.2 and the Splunk CloudConnect SDK versions below 3.1.3, requests to third-party APIs through the RE…

Fix: 3.1.3 / 4.1.2+
Fix from $1,600 2023-02-14
Splunk HIGH 8.8
CVE-2022-43565

In Splunk Enterprise versions below 8.2.9 and 8.1.12, the way that the ‘tstats command handles Javascript Object Notation (JSON) lets an attacker byp…

Fix: 8.1.12 / 8.2.9+
Fix from $1,950 2022-11-04
Splunk HIGH 8.8
CVE-2022-43567

In Splunk Enterprise versions below 8.2.9, 8.1.12, and 9.0.2, an authenticated user can run arbitrary operating system commands remotely through the …

Fix: 8.1.12 / 8.2.9+
Fix from $1,950 2022-11-04
Splunk HIGH 8.0
CVE-2022-43566

In Splunk Enterprise versions below 8.2.9, 8.1.12, and 9.0.2, an authenticated user can run risky commands using a more privileged user’s permissions…

Fix: 8.1.12 / 8.2.9+
Fix from $1,950 2022-11-04
Splunk MEDIUM 6.5
CVE-2022-43570

In Splunk Enterprise versions below 8.1.12, 8.2.9, and 9.0.2, an authenticated user can perform an extensible markup language (XML) external entity (…

Fix: 8.1.12 / 8.2.9+
Fix from $1,600 2022-11-04
Splunk MEDIUM 6.5
CVE-2022-43572

In Splunk Enterprise versions below 8.2.9, 8.1.12, and 9.0.2, sending a malformed file through the Splunk-to-Splunk (S2S) or HTTP Event Collector (HE…

Fix: 8.1.12 / 8.2.9+
Fix from $1,600 2022-11-04
Splunk MEDIUM 6.1
CVE-2022-43568EPSS 43%

In Splunk Enterprise versions below 8.1.12, 8.2.9, and 9.0.2, a View allows for a Reflected Cross Site Scripting via JavaScript Object Notation (JSON…

Fix: 8.1.12 / 8.2.9+
Fix from $1,600 2022-11-04
Splunk MEDIUM 5.4
CVE-2022-43569

In Splunk Enterprise versions below 8.1.12, 8.2.9, and 9.0.2, an authenticated user can inject and store arbitrary scripts that can lead to persisten…

Fix: 8.1.12 / 8.2.9+
Fix from $1,600 2022-11-04
Splunk HIGH 8.8
CVE-2022-43563

In Splunk Enterprise versions below 8.2.9 and 8.1.12, the way that the rex search command handles field names lets an attacker bypass SPL safeguards…

Fix: 8.1.12 / 8.2.9+
Fix from $1,950 2022-11-04
Splunk MEDIUM 6.5
CVE-2022-43564

In Splunk Enterprise versions below 8.1.12, 8.2.9, and 9.0.2, a remote user who can create search macros and schedule search reports can cause a deni…

Fix: 8.1.12 / 8.2.9+
Fix from $1,600 2022-11-04
Splunk MEDIUM 5.4
CVE-2022-43562

In Splunk Enterprise versions below 8.1.12, 8.2.9, and 9.0.2, Splunk Enterprise fails to properly validate and escape the Host header, which could le…

Fix: 8.1.12 / 8.2.9+
Fix from $1,600 2022-11-04
Splunk HIGH 8.8
CVE-2022-43571EPSS 13%

In Splunk Enterprise versions below 8.2.9, 8.1.12, and 9.0.2, an authenticated user can execute arbitrary code through the dashboard PDF generation c…

Fix: 8.1.12 / 8.2.9+
Fix from $1,950 2022-11-03
Splunk CRITICAL 9.8
CVE-2022-37437

When using Ingest Actions to configure a destination that resides on Amazon Simple Storage Service (S3) in Splunk Web, TLS certificate validation is …

Mitigation only
Fix from $2,300 2022-08-16
Splunk MEDIUM 5.5
CVE-2022-37439

In Splunk Enterprise and Universal Forwarder versions in the following table, indexing a specially crafted ZIP file using the file monitoring input c…

Fix: 8.1.11 / 8.2.7.1+
Fix from $1,600 2022-08-16
Splunk CRITICAL 10.0
CVE-2022-32158

Splunk Enterprise deployment servers in versions before 8.1.10.1, 8.2.6.1, and 9.0 let clients deploy forwarder bundles to other deployment clients t…

Fix: 9.0+
Fix from $2,300 2022-06-15
Splunk HIGH 8.1
CVE-2022-32154

Dashboards in Splunk Enterprise versions before 9.0 might let an attacker inject risky search commands into a form token when the token is used in a …

Fix: 8.2.2106 / 9.0+
Fix from $1,950 2022-06-15
Splunk HIGH 8.1
CVE-2022-32156

In Splunk Enterprise and Universal Forwarder versions before 9.0, the Splunk command-line interface (CLI) did not validate TLS certificates while con…

Fix: 9.0+
Fix from $1,950 2022-06-15