Vulnerability index

Browse CVEs

153 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Splunk HIGH 7.5
CVE-2022-32155

In universal forwarder versions before 9.0, management services are available remotely by default. When not required, it introduces a potential expos…

Fix: 8.2.2106 / 9.0+
Fix from $1,950 2022-06-15
Splunk HIGH 7.5
CVE-2022-32157

Splunk Enterprise deployment servers in versions before 9.0 allow unauthenticated downloading of forwarder bundles. Remediation requires you to updat…

Fix: 9.0+
Fix from $1,950 2022-06-15
Splunk CRITICAL 9.1
CVE-2022-32151

The httplib and urllib Python libraries that Splunk shipped with Splunk Enterprise did not validate certificates using the certificate authority (CA)…

Fix: 8.2.2203 / 9.0+
Fix from $2,300 2022-06-15
Splunk HIGH 8.1
CVE-2022-32153

Splunk Enterprise peers in Splunk Enterprise versions before 9.0 and Splunk Cloud Platform versions before 8.2.2203 did not validate the TLS certific…

Fix: 8.2.2203 / 9.0+
Fix from $1,950 2022-06-15
Splunk HIGH 7.2
CVE-2022-32152

Splunk Enterprise peers in Splunk Enterprise versions before 9.0 and Splunk Cloud Platform versions before 8.2.2203 did not validate the TLS certific…

Fix: 8.2.2203 / 9.0+
Fix from $1,950 2022-06-15
Splunk HIGH 8.8
CVE-2022-26889

In Splunk Enterprise versions before 8.1.2, the uri path to load a relative resource within a web page is vulnerable to path traversal. It allows an …

Fix: 8.1.2+
Fix from $1,950 2022-05-06
Splunk HIGH 8.1
CVE-2021-26253

A potential vulnerability in Splunk Enterprise's implementation of DUO MFA allows for bypassing the MFA verification in Splunk Enterprise versions be…

Fix: 8.1.6+
Fix from $1,950 2022-05-06
Splunk HIGH 7.8
CVE-2021-42743

A misconfiguration in the node default path allows for local privilege escalation from a lower privileged user to the Splunk user in Splunk Enterpris…

Fix: 8.1.1+
Fix from $1,950 2022-05-06
Splunk HIGH 7.5
CVE-2021-31559

A crafted request bypasses S2S TCP Token authentication writing arbitrary events to an index in Splunk Enterprise Indexer 8.1 versions before 8.1.5 a…

Fix: 8.1.5+
Fix from $1,950 2022-05-06
Splunk MEDIUM 6.1
CVE-2022-27183

The Monitoring Console app configured in Distributed mode allows for a Reflected XSS in a query parameter in Splunk Enterprise versions before 8.1.4.…

Fix: 8.1.4+
Fix from $1,600 2022-05-06
Splunk MEDIUM 5.3
CVE-2021-33845

The Splunk Enterprise REST API allows enumeration of usernames via the lockout error message. The potential vulnerability impacts Splunk Enterprise i…

Fix: 8.1.7+
Fix from $1,600 2022-05-06
Splunk HIGH 7.5
CVE-2021-3422

The lack of validation of a key-value field in the Splunk-to-Splunk protocol results in a denial-of-service in Splunk Enterprise instances configured…

Fix: 7.3.9 / 8.0.9+
Fix from $1,950 2022-03-25
Splunk HIGH 7.8
CVE-2013-6773

Splunk 5.0.3 has an Unquoted Service Path in Windows for Universal Forwarder which can allow an attacker to escalate privileges

Fix: 5.0.3+
Fix from $1,950 2020-01-23
Software Development Kit HIGH 8.1
CVE-2019-5729

Splunk-SDK-Python before 1.6.6 does not properly verify untrusted TLS server certificates, which could result in man-in-the-middle attacks.

Fix: 1.6.6+
Fix from $1,950 2019-03-21
Splunk MEDIUM 5.4
CVE-2019-5727

Splunk Web in Splunk Enterprise 6.5.x before 6.5.5, 6.4.x before 6.4.9, 6.3.x before 6.3.12, 6.2.x before 6.2.14, 6.1.x before 6.1.14, and 6.0.x befo…

Fix: 6.0.15 / 6.1.14+
Fix from $1,600 2019-02-21
Splunk HIGH 7.5
CVE-2018-7429

Splunkd in Splunk Enterprise 6.2.x before 6.2.14 6.3.x before 6.3.11, and 6.4.x before 6.4.8; and Splunk Light before 6.5.0 allow remote attackers to…

Fix: 6.2.14 / 6.3.11+
Fix from $1,950 2018-10-23
Splunk HIGH 7.5
CVE-2018-7432

Splunk Enterprise 6.2.x before 6.2.14, 6.3.x before 6.3.10, 6.4.x before 6.4.7, and 6.5.x before 6.5.3; and Splunk Light before 6.6.0 allow remote at…

Fix: 6.2.14 / 6.3.10+
Fix from $1,950 2018-10-23
Splunk MEDIUM 6.5
CVE-2018-7431

Directory traversal vulnerability in the Splunk Django App in Splunk Enterprise 6.0.x before 6.0.14, 6.1.x before 6.1.13, 6.2.x before 6.2.14, 6.3.x …

Fix: 6.0.14 / 6.1.13+
Fix from $1,600 2018-10-23
Splunk MEDIUM 6.1
CVE-2018-7427

Cross-site scripting (XSS) vulnerability in Splunk Web in Splunk Enterprise 6.0.x before 6.0.14, 6.1.x before 6.1.13, 6.2.x before 6.2.14, 6.3.x befo…

Fix: 6.0.14 / 6.1.13+
Fix from $1,600 2018-10-23
Splunk HIGH 7.0
CVE-2017-18348

Splunk Enterprise 6.6.x, when configured to run as root but drop privileges to a specific non-root account, allows local users to gain privileges by …

Fix: after 6.6.11
Fix from $1,950 2018-10-19
Splunk MEDIUM 5.3
CVE-2018-11409EPSS 98%

Splunk through 7.0.1 allows information disclosure by appending __raw/services/server/info/server-info?output_mode=json to a query, as demonstrated b…

Fix: after 7.0.1
Fix from $1,600 2018-06-08
Splunk CRITICAL 9.8
CVE-2017-17067

Splunk Web in Splunk Enterprise 7.0.x before 7.0.0.1, 6.6.x before 6.6.3.2, 6.5.x before 6.5.6, 6.4.x before 6.4.9, and 6.3.x before 6.3.12, when the…

Fix: 6.3.12 / 6.4.9+
Fix from $2,300 2017-11-30
Splunk MEDIUM 6.1
CVE-2016-4857

Open redirect vulnerability in Splunk Enterprise 6.4.x prior to 6.4.2, Splunk Enterprise 6.3.x prior to 6.3.6, Splunk Enterprise 6.2.x prior to 6.2.1…

Fix: after 6.4.2
Fix from $1,600 2017-05-12
Splunk MEDIUM 6.1
CVE-2016-4859

Open redirect vulnerability in Splunk Enterprise 6.4.x prior to 6.4.3, Splunk Enterprise 6.3.x prior to 6.3.6, Splunk Enterprise 6.2.x prior to 6.2.1…

Fix: after 6.4.2
Fix from $1,600 2017-05-12
Hadoop Connect HIGH 8.8
CVE-2017-7565

Splunk Hadoop Connect App has a path traversal vulnerability that allows remote authenticated users to execute arbitrary code, aka ERP-2041.

Mitigation only
Fix from $1,950 2017-04-06
Splunk MEDIUM 6.5
CVE-2017-5880

Splunk Web in Splunk Enterprise versions 6.5.x before 6.5.2, 6.4.x before 6.4.5, 6.3.x before 6.3.9, 6.2.x before 6.2.13, 6.1.x before 6.1.12, 6.0.x …

Patch available
Fix from $1,600 2017-02-04
Splunk CRITICAL 9.8
CVE-2016-10126

Splunk Web in Splunk Enterprise 5.0.x before 5.0.17, 6.0.x before 6.0.13, 6.1.x before 6.1.12, 6.2.x before 6.2.12, 6.3.x before 6.3.8, and 6.4.x bef…

Mitigation only
Fix from $2,300 2017-01-10
Splunk HIGH 9.3
CVE-2013-6771

Directory traversal vulnerability in the collect script in Splunk before 5.0.5 allows remote attackers to execute arbitrary commands via a .. (dot do…

Fix: after 5.0.4
Fix from $1,950 2014-08-07
Splunk HIGH 9.0
CVE-2013-7394

The "runshellscript echo.sh" script in Splunk before 5.0.5 allows remote authenticated users to execute arbitrary commands via a crafted string. NOT…

Fix: after 5.0.4
Fix from $1,950 2014-08-07
Splunk HIGH 9.3
CVE-2011-4644EPSS 8%

Splunk 4.2.5 and earlier, when a Free license is selected, enables potentially undesirable functionality within an environment that intentionally doe…

Fix: after 4.2.5
Fix from $1,950 2012-01-03