Vulnerability index

Browse CVEs

153 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

MEDIUM 6.5 CVE-2023-32706 On Splunk Enterprise versions below 9.0.5, 8.2.11, and 8.1.14, an unauthenticated attacker can send specially-crafted messages to the XML parser with… Splunk 8.1.14 / 8.2.11+ Fix from $1,6002023-06-01 MEDIUM 6.5 CVE-2023-32716 In Splunk Enterprise versions below 9.0.5, 8.2.11, and 8.1.14, and Splunk Cloud Platform versions below 9.0.2303.100, an attacker can exploit a vulne… Splunk 8.1.14 / 8.2.11+ Fix from $1,6002023-06-01 MEDIUM 6.1 CVE-2023-32715 In the Splunk App for Lookup File Editing versions below 4.0.1, a user can insert potentially malicious JavaScript code into the app, which causes th… Splunk App For Lookup File Editing 4.0.1+ Fix from $1,6002023-06-01 MEDIUM 5.4 CVE-2023-32711 In Splunk Enterprise versions below 9.0.5, 8.2.11, and 8.1.14, a Splunk dashboard view lets a low-privileged user exploit a vulnerability in the Boot… Splunk 8.1.14 / 8.2.11+ Fix from $1,6002023-06-01 MEDIUM 5.3 CVE-2023-32710 In Splunk Enterprise versions below 9.0.5, 8.2.11, and 8.1.14, and in Splunk Cloud Platform versions below 9.0.2303.100, a low-privileged user can pe… Splunk 8.1.14 / 8.2.11+ Fix from $1,6002023-06-01 HIGH 8.8 CVE-2023-22935 In Splunk Enterprise versions below 8.1.13, 8.2.10, and 9.0.4, the ‘display.page.search.patterns.sensitivity’ search parameter lets a search bypass S… Splunk 8.1.13 / 8.2.10+ Fix from $1,9502023-02-14 HIGH 8.8 CVE-2023-22939 In Splunk Enterprise versions below 8.1.13, 8.2.10, and 9.0.4, the ‘map’ search processing language (SPL) command lets a search bypass SPL safeguards… Splunk 8.1.13 / 8.2.10+ Fix from $1,9502023-02-14 HIGH 8.0 CVE-2023-22934 In Splunk Enterprise versions below 8.1.13, 8.2.10, and 9.0.4, the ‘pivot’ search processing language (SPL) command lets a search bypass SPL safeguar… Splunk 8.1.13 / 8.2.10+ Fix from $1,9502023-02-14 HIGH 7.5 CVE-2023-22941 In Splunk Enterprise versions below 8.1.13, 8.2.10, and 9.0.4, an improperly-formatted ‘INGEST_EVAL’ parameter in a Field Transformation crashes the … Splunk 8.1.13 / 8.2.10+ Fix from $1,9502023-02-14 MEDIUM 6.3 CVE-2023-22936 In Splunk Enterprise versions below 8.1.13, 8.2.10, and 9.0.4, the ‘search_listener’ parameter in a search allows for a blind server-side request for… Splunk 8.1.13 / 8.2.10+ Fix from $1,6002023-02-14 MEDIUM 6.1 CVE-2023-22932 In Splunk Enterprise 9.0 versions before 9.0.4, a View allows for Cross-Site Scripting (XSS) through the error message in a Base64-encoded image. The… Splunk 9.0.4 / 9.0.2209.3+ Fix from $1,6002023-02-14 MEDIUM 6.1 CVE-2023-22933 In Splunk Enterprise versions below 8.1.13, 8.2.10, and 9.0.4, a View allows for Cross-Site Scripting (XSS) in an extensible mark-up language (XML) V… Splunk 8.1.13 / 8.2.10+ Fix from $1,6002023-02-14 MEDIUM 5.7 CVE-2023-22940 In Splunk Enterprise versions below 8.1.13, 8.2.10, and 9.0.4, aliases of the ‘collect’ search processing language (SPL) command, including ‘summaryi… Splunk 8.1.13 / 8.2.10+ Fix from $1,6002023-02-14 MEDIUM 5.3 CVE-2023-22943 In Splunk Add-on Builder (AoB) versions below 4.1.2 and the Splunk CloudConnect SDK versions below 3.1.3, requests to third-party APIs through the RE… Add On Builder 3.1.3 / 4.1.2+ Fix from $1,6002023-02-14 HIGH 8.8 CVE-2022-43565 In Splunk Enterprise versions below 8.2.9 and 8.1.12, the way that the ‘tstats command handles Javascript Object Notation (JSON) lets an attacker byp… Splunk 8.1.12 / 8.2.9+ Fix from $1,9502022-11-04 HIGH 8.8 CVE-2022-43567 In Splunk Enterprise versions below 8.2.9, 8.1.12, and 9.0.2, an authenticated user can run arbitrary operating system commands remotely through the … Splunk 8.1.12 / 8.2.9+ Fix from $1,9502022-11-04 HIGH 8.0 CVE-2022-43566 In Splunk Enterprise versions below 8.2.9, 8.1.12, and 9.0.2, an authenticated user can run risky commands using a more privileged user’s permissions… Splunk 8.1.12 / 8.2.9+ Fix from $1,9502022-11-04 MEDIUM 6.5 CVE-2022-43570 In Splunk Enterprise versions below 8.1.12, 8.2.9, and 9.0.2, an authenticated user can perform an extensible markup language (XML) external entity (… Splunk 8.1.12 / 8.2.9+ Fix from $1,6002022-11-04 MEDIUM 6.5 CVE-2022-43572 In Splunk Enterprise versions below 8.2.9, 8.1.12, and 9.0.2, sending a malformed file through the Splunk-to-Splunk (S2S) or HTTP Event Collector (HE… Splunk 8.1.12 / 8.2.9+ Fix from $1,6002022-11-04 MEDIUM 6.1 CVE-2022-43568EPSS 43% In Splunk Enterprise versions below 8.1.12, 8.2.9, and 9.0.2, a View allows for a Reflected Cross Site Scripting via JavaScript Object Notation (JSON… Splunk 8.1.12 / 8.2.9+ Fix from $1,6002022-11-04 MEDIUM 5.4 CVE-2022-43569 In Splunk Enterprise versions below 8.1.12, 8.2.9, and 9.0.2, an authenticated user can inject and store arbitrary scripts that can lead to persisten… Splunk 8.1.12 / 8.2.9+ Fix from $1,6002022-11-04 HIGH 8.8 CVE-2022-43563 In Splunk Enterprise versions below 8.2.9 and 8.1.12, the way that the rex search command handles field names lets an attacker bypass SPL safeguards… Splunk 8.1.12 / 8.2.9+ Fix from $1,9502022-11-04 MEDIUM 6.5 CVE-2022-43564 In Splunk Enterprise versions below 8.1.12, 8.2.9, and 9.0.2, a remote user who can create search macros and schedule search reports can cause a deni… Splunk 8.1.12 / 8.2.9+ Fix from $1,6002022-11-04 MEDIUM 5.4 CVE-2022-43562 In Splunk Enterprise versions below 8.1.12, 8.2.9, and 9.0.2, Splunk Enterprise fails to properly validate and escape the Host header, which could le… Splunk 8.1.12 / 8.2.9+ Fix from $1,6002022-11-04 HIGH 8.8 CVE-2022-43571EPSS 13% In Splunk Enterprise versions below 8.2.9, 8.1.12, and 9.0.2, an authenticated user can execute arbitrary code through the dashboard PDF generation c… Splunk 8.1.12 / 8.2.9+ Fix from $1,9502022-11-03 CRITICAL 9.8 CVE-2022-37437 When using Ingest Actions to configure a destination that resides on Amazon Simple Storage Service (S3) in Splunk Web, TLS certificate validation is … Splunk Mitigation only Fix from $2,3002022-08-16 MEDIUM 5.5 CVE-2022-37439 In Splunk Enterprise and Universal Forwarder versions in the following table, indexing a specially crafted ZIP file using the file monitoring input c… Splunk 8.1.11 / 8.2.7.1+ Fix from $1,6002022-08-16 CRITICAL 10.0 CVE-2022-32158 Splunk Enterprise deployment servers in versions before 8.1.10.1, 8.2.6.1, and 9.0 let clients deploy forwarder bundles to other deployment clients t… Splunk 9.0+ Fix from $2,3002022-06-15 HIGH 8.1 CVE-2022-32154 Dashboards in Splunk Enterprise versions before 9.0 might let an attacker inject risky search commands into a form token when the token is used in a … Splunk 8.2.2106 / 9.0+ Fix from $1,9502022-06-15 HIGH 8.1 CVE-2022-32156 In Splunk Enterprise and Universal Forwarder versions before 9.0, the Splunk command-line interface (CLI) did not validate TLS certificates while con… Splunk 9.0+ Fix from $1,9502022-06-15