Vulnerability index

Browse CVEs

153 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

HIGH 7.5 CVE-2022-32155 In universal forwarder versions before 9.0, management services are available remotely by default. When not required, it introduces a potential expos… Splunk 8.2.2106 / 9.0+ Fix from $1,9502022-06-15 HIGH 7.5 CVE-2022-32157 Splunk Enterprise deployment servers in versions before 9.0 allow unauthenticated downloading of forwarder bundles. Remediation requires you to updat… Splunk 9.0+ Fix from $1,9502022-06-15 CRITICAL 9.1 CVE-2022-32151 The httplib and urllib Python libraries that Splunk shipped with Splunk Enterprise did not validate certificates using the certificate authority (CA)… Splunk 8.2.2203 / 9.0+ Fix from $2,3002022-06-15 HIGH 8.1 CVE-2022-32153 Splunk Enterprise peers in Splunk Enterprise versions before 9.0 and Splunk Cloud Platform versions before 8.2.2203 did not validate the TLS certific… Splunk 8.2.2203 / 9.0+ Fix from $1,9502022-06-15 HIGH 7.2 CVE-2022-32152 Splunk Enterprise peers in Splunk Enterprise versions before 9.0 and Splunk Cloud Platform versions before 8.2.2203 did not validate the TLS certific… Splunk 8.2.2203 / 9.0+ Fix from $1,9502022-06-15 HIGH 8.8 CVE-2022-26889 In Splunk Enterprise versions before 8.1.2, the uri path to load a relative resource within a web page is vulnerable to path traversal. It allows an … Splunk 8.1.2+ Fix from $1,9502022-05-06 HIGH 8.1 CVE-2021-26253 A potential vulnerability in Splunk Enterprise's implementation of DUO MFA allows for bypassing the MFA verification in Splunk Enterprise versions be… Splunk 8.1.6+ Fix from $1,9502022-05-06 HIGH 7.8 CVE-2021-42743 A misconfiguration in the node default path allows for local privilege escalation from a lower privileged user to the Splunk user in Splunk Enterpris… Splunk 8.1.1+ Fix from $1,9502022-05-06 HIGH 7.5 CVE-2021-31559 A crafted request bypasses S2S TCP Token authentication writing arbitrary events to an index in Splunk Enterprise Indexer 8.1 versions before 8.1.5 a… Splunk 8.1.5+ Fix from $1,9502022-05-06 MEDIUM 6.1 CVE-2022-27183 The Monitoring Console app configured in Distributed mode allows for a Reflected XSS in a query parameter in Splunk Enterprise versions before 8.1.4.… Splunk 8.1.4+ Fix from $1,6002022-05-06 MEDIUM 5.3 CVE-2021-33845 The Splunk Enterprise REST API allows enumeration of usernames via the lockout error message. The potential vulnerability impacts Splunk Enterprise i… Splunk 8.1.7+ Fix from $1,6002022-05-06 HIGH 7.5 CVE-2021-3422 The lack of validation of a key-value field in the Splunk-to-Splunk protocol results in a denial-of-service in Splunk Enterprise instances configured… Splunk 7.3.9 / 8.0.9+ Fix from $1,9502022-03-25 HIGH 7.8 CVE-2013-6773 Splunk 5.0.3 has an Unquoted Service Path in Windows for Universal Forwarder which can allow an attacker to escalate privileges Splunk 5.0.3+ Fix from $1,9502020-01-23 HIGH 8.1 CVE-2019-5729 Splunk-SDK-Python before 1.6.6 does not properly verify untrusted TLS server certificates, which could result in man-in-the-middle attacks. Software Development Kit 1.6.6+ Fix from $1,9502019-03-21 MEDIUM 5.4 CVE-2019-5727 Splunk Web in Splunk Enterprise 6.5.x before 6.5.5, 6.4.x before 6.4.9, 6.3.x before 6.3.12, 6.2.x before 6.2.14, 6.1.x before 6.1.14, and 6.0.x befo… Splunk 6.0.15 / 6.1.14+ Fix from $1,6002019-02-21 HIGH 7.5 CVE-2018-7429 Splunkd in Splunk Enterprise 6.2.x before 6.2.14 6.3.x before 6.3.11, and 6.4.x before 6.4.8; and Splunk Light before 6.5.0 allow remote attackers to… Splunk 6.2.14 / 6.3.11+ Fix from $1,9502018-10-23 HIGH 7.5 CVE-2018-7432 Splunk Enterprise 6.2.x before 6.2.14, 6.3.x before 6.3.10, 6.4.x before 6.4.7, and 6.5.x before 6.5.3; and Splunk Light before 6.6.0 allow remote at… Splunk 6.2.14 / 6.3.10+ Fix from $1,9502018-10-23 MEDIUM 6.5 CVE-2018-7431 Directory traversal vulnerability in the Splunk Django App in Splunk Enterprise 6.0.x before 6.0.14, 6.1.x before 6.1.13, 6.2.x before 6.2.14, 6.3.x … Splunk 6.0.14 / 6.1.13+ Fix from $1,6002018-10-23 MEDIUM 6.1 CVE-2018-7427 Cross-site scripting (XSS) vulnerability in Splunk Web in Splunk Enterprise 6.0.x before 6.0.14, 6.1.x before 6.1.13, 6.2.x before 6.2.14, 6.3.x befo… Splunk 6.0.14 / 6.1.13+ Fix from $1,6002018-10-23 HIGH 7.0 CVE-2017-18348 Splunk Enterprise 6.6.x, when configured to run as root but drop privileges to a specific non-root account, allows local users to gain privileges by … Splunk after 6.6.11 Fix from $1,9502018-10-19 MEDIUM 5.3 CVE-2018-11409EPSS 98% Splunk through 7.0.1 allows information disclosure by appending __raw/services/server/info/server-info?output_mode=json to a query, as demonstrated b… Splunk after 7.0.1 Fix from $1,6002018-06-08 CRITICAL 9.8 CVE-2017-17067 Splunk Web in Splunk Enterprise 7.0.x before 7.0.0.1, 6.6.x before 6.6.3.2, 6.5.x before 6.5.6, 6.4.x before 6.4.9, and 6.3.x before 6.3.12, when the… Splunk 6.3.12 / 6.4.9+ Fix from $2,3002017-11-30 MEDIUM 6.1 CVE-2016-4857 Open redirect vulnerability in Splunk Enterprise 6.4.x prior to 6.4.2, Splunk Enterprise 6.3.x prior to 6.3.6, Splunk Enterprise 6.2.x prior to 6.2.1… Splunk after 6.4.2 Fix from $1,6002017-05-12 MEDIUM 6.1 CVE-2016-4859 Open redirect vulnerability in Splunk Enterprise 6.4.x prior to 6.4.3, Splunk Enterprise 6.3.x prior to 6.3.6, Splunk Enterprise 6.2.x prior to 6.2.1… Splunk after 6.4.2 Fix from $1,6002017-05-12 HIGH 8.8 CVE-2017-7565 Splunk Hadoop Connect App has a path traversal vulnerability that allows remote authenticated users to execute arbitrary code, aka ERP-2041. Hadoop Connect Mitigation only Fix from $1,9502017-04-06 MEDIUM 6.5 CVE-2017-5880 Splunk Web in Splunk Enterprise versions 6.5.x before 6.5.2, 6.4.x before 6.4.5, 6.3.x before 6.3.9, 6.2.x before 6.2.13, 6.1.x before 6.1.12, 6.0.x … Splunk Patch available Fix from $1,6002017-02-04 CRITICAL 9.8 CVE-2016-10126 Splunk Web in Splunk Enterprise 5.0.x before 5.0.17, 6.0.x before 6.0.13, 6.1.x before 6.1.12, 6.2.x before 6.2.12, 6.3.x before 6.3.8, and 6.4.x bef… Splunk Mitigation only Fix from $2,3002017-01-10 HIGH 9.3 CVE-2013-6771 Directory traversal vulnerability in the collect script in Splunk before 5.0.5 allows remote attackers to execute arbitrary commands via a .. (dot do… Splunk after 5.0.4 Fix from $1,9502014-08-07 HIGH 9.0 CVE-2013-7394 The "runshellscript echo.sh" script in Splunk before 5.0.5 allows remote authenticated users to execute arbitrary commands via a crafted string. NOT… Splunk after 5.0.4 Fix from $1,9502014-08-07 HIGH 9.3 CVE-2011-4644EPSS 8% Splunk 4.2.5 and earlier, when a Free license is selected, enables potentially undesirable functionality within an environment that intentionally doe… Splunk after 4.2.5 Fix from $1,9502012-01-03