{"api_version":"1","generated_at":"2026-07-23T07:12:21+00:00","cve":"CVE-2015-6514","urls":{"html":"https://cve.report/CVE-2015-6514","api":"https://cve.report/api/cve/CVE-2015-6514.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2015-6514","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2015-6514"},"summary":{"title":"CVE-2015-6514","description":"Cross-site scripting (XSS) vulnerability in the Dashboard in Splunk Enterprise 6.2.x before 6.2.4 and Splunk Light 6.2.x before 6.2.4 allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors.","state":"PUBLISHED","assigner":"mitre","published_at":"2015-08-18 15:59:15","updated_at":"2026-05-06 22:30:45"},"problem_types":["CWE-79","n/a"],"metrics":[{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"4.3","severity":"","vector":"AV:N/AC:M/Au:N/C:N/I:P/A:N","data":{"version":"2.0","vectorString":"AV:N/AC:M/Au:N/C:N/I:P/A:N","baseScore":4.3,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"NONE","integrityImpact":"PARTIAL","availabilityImpact":"NONE"}}],"references":[{"url":"http://www.splunk.com/view/SP-CAAAN7C","name":"http://www.splunk.com/view/SP-CAAAN7C","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"],"title":"Splunk Enterprise 6.2.4 and Splunk Light 6.2.4 address two vulnerabilities | Splunk","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.securitytracker.com/id/1032859","name":"http://www.securitytracker.com/id/1032859","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Splunk Enterprise and Splunk Light Input Validation Flaw Lets Remote Users Conduct Cross-Site Scripting Attacks - SecurityTracker","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2015-6514","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2015-6514","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"n/a","product":"n/a","version":"affected n/a","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2015","cve_id":"6514","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"splunk","cpe5":"splunk","cpe6":"6.2.0","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"enterprise","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2015","cve_id":"6514","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"splunk","cpe5":"splunk","cpe6":"6.2.0","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"light","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2015","cve_id":"6514","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"splunk","cpe5":"splunk","cpe6":"6.2.1","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"enterprise","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2015","cve_id":"6514","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"splunk","cpe5":"splunk","cpe6":"6.2.1","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"light","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2015","cve_id":"6514","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"splunk","cpe5":"splunk","cpe6":"6.2.2","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"enterprise","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2015","cve_id":"6514","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"splunk","cpe5":"splunk","cpe6":"6.2.2","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"light","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2015","cve_id":"6514","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"splunk","cpe5":"splunk","cpe6":"6.2.3","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"enterprise","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2015","cve_id":"6514","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"splunk","cpe5":"splunk","cpe6":"6.2.3","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"light","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-06T07:22:22.254Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"http://www.splunk.com/view/SP-CAAAN7C"},{"name":"1032859","tags":["vdb-entry","x_refsource_SECTRACK","x_transferred"],"url":"http://www.securitytracker.com/id/1032859"}],"title":"CVE Program Container"}],"cna":{"affected":[{"product":"n/a","vendor":"n/a","versions":[{"status":"affected","version":"n/a"}]}],"descriptions":[{"lang":"en","value":"Cross-site scripting (XSS) vulnerability in the Dashboard in Splunk Enterprise 6.2.x before 6.2.4 and Splunk Light 6.2.x before 6.2.4 allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors."}],"problemTypes":[{"descriptions":[{"description":"n/a","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2015-08-18T15:00:00.000Z","orgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","shortName":"mitre"},"references":[{"tags":["x_refsource_CONFIRM"],"url":"http://www.splunk.com/view/SP-CAAAN7C"},{"name":"1032859","tags":["vdb-entry","x_refsource_SECTRACK"],"url":"http://www.securitytracker.com/id/1032859"}],"x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"cve@mitre.org","ID":"CVE-2015-6514","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"Cross-site scripting (XSS) vulnerability in the Dashboard in Splunk Enterprise 6.2.x before 6.2.4 and Splunk Light 6.2.x before 6.2.4 allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"http://www.splunk.com/view/SP-CAAAN7C","refsource":"CONFIRM","url":"http://www.splunk.com/view/SP-CAAAN7C"},{"name":"1032859","refsource":"SECTRACK","url":"http://www.securitytracker.com/id/1032859"}]}}}},"cveMetadata":{"assignerOrgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","assignerShortName":"mitre","cveId":"CVE-2015-6514","datePublished":"2015-08-18T15:00:00.000Z","dateReserved":"2015-08-18T00:00:00.000Z","dateUpdated":"2024-09-16T20:07:04.560Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2015-08-18 15:59:15","lastModifiedDate":"2026-05-06 22:30:45","problem_types":["CWE-79","n/a"],"metrics":{"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:M/Au:N/C:N/I:P/A:N","baseScore":4.3,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"NONE","integrityImpact":"PARTIAL","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":8.6,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":true}]},"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:splunk:splunk:6.2.0:*:*:*:enterprise:*:*:*","matchCriteriaId":"6A1B5DB3-86EE-43D5-8FA2-C62CB0F1589B"},{"vulnerable":true,"criteria":"cpe:2.3:a:splunk:splunk:6.2.0:*:*:*:light:*:*:*","matchCriteriaId":"117453BF-BE18-4FDD-8A8B-9AD6F48B57D1"},{"vulnerable":true,"criteria":"cpe:2.3:a:splunk:splunk:6.2.1:*:*:*:enterprise:*:*:*","matchCriteriaId":"1AD74B94-BA4C-4679-AD80-AB268F930800"},{"vulnerable":true,"criteria":"cpe:2.3:a:splunk:splunk:6.2.1:*:*:*:light:*:*:*","matchCriteriaId":"A76D10BD-83F3-4E66-8F6C-46542B342C64"},{"vulnerable":true,"criteria":"cpe:2.3:a:splunk:splunk:6.2.2:*:*:*:enterprise:*:*:*","matchCriteriaId":"F6B51A1C-15FA-4F09-BEC0-2365EA1B2320"},{"vulnerable":true,"criteria":"cpe:2.3:a:splunk:splunk:6.2.2:*:*:*:light:*:*:*","matchCriteriaId":"713870AD-3A19-4E1C-8D78-51273E0A2865"},{"vulnerable":true,"criteria":"cpe:2.3:a:splunk:splunk:6.2.3:*:*:*:enterprise:*:*:*","matchCriteriaId":"3DF8E96E-9A0C-4865-9891-6FF686FAFC10"},{"vulnerable":true,"criteria":"cpe:2.3:a:splunk:splunk:6.2.3:*:*:*:light:*:*:*","matchCriteriaId":"B9935FC7-EFCF-4D79-A275-51DBEB1E3A8C"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2015","CveId":"6514","Ordinal":"1","Title":"CVE-2015-6514","CVE":"CVE-2015-6514","Year":"2015"},"notes":[{"CveYear":"2015","CveId":"6514","Ordinal":"1","NoteData":"Cross-site scripting (XSS) vulnerability in the Dashboard in Splunk Enterprise 6.2.x before 6.2.4 and Splunk Light 6.2.x before 6.2.4 allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors.","Type":"Description","Title":"CVE-2015-6514"},{"CveYear":"2015","CveId":"6514","Ordinal":"2","NoteData":"2015-08-18","Type":"Other","Title":"Published"}]}}}