{"api_version":"1","generated_at":"2026-07-23T23:02:13+00:00","cve":"CVE-2016-4856","urls":{"html":"https://cve.report/CVE-2016-4856","api":"https://cve.report/api/cve/CVE-2016-4856.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2016-4856","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2016-4856"},"summary":{"title":"CVE-2016-4856","description":"Cross-site scripting vulnerability in Splunk Enterprise 6.3.x prior to 6.3.5 and Splunk Light 6.3.x prior to 6.3.5 allows attacker with administrator rights to inject arbitrary web script or HTML via unspecified vectors.","state":"PUBLISHED","assigner":"jpcert","published_at":"2017-05-12 18:29:00","updated_at":"2025-04-20 01:37:25"},"problem_types":["CWE-79","Cross-site scripting"],"metrics":[{"version":"3.0","source":"nvd@nist.gov","type":"Primary","score":"4.8","severity":"MEDIUM","vector":"CVSS:3.0/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N","data":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N","baseScore":4.8,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"HIGH","userInteraction":"REQUIRED","scope":"CHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE"}},{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"3.5","severity":"","vector":"AV:N/AC:M/Au:S/C:N/I:P/A:N","data":{"version":"2.0","vectorString":"AV:N/AC:M/Au:S/C:N/I:P/A:N","baseScore":3.5,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"SINGLE","confidentialityImpact":"NONE","integrityImpact":"PARTIAL","availabilityImpact":"NONE"}}],"references":[{"url":"https://jvn.jp/en/jp/JVN71462075/index.html","name":"https://jvn.jp/en/jp/JVN71462075/index.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory","VDB Entry"],"title":"JVN#71462075: Splunk Enterprise and Splunk Lite vulnerable to cross-site scripting","mime":"text/xml","httpstatus":"200","archivestatus":"200"},{"url":"https://www.splunk.com/view/SP-CAAAPN9","name":"https://www.splunk.com/view/SP-CAAAPN9","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"],"title":"Splunk Enterprise 6.3.5 and Splunk Light 6.3.5 address two vulnerabilities | Splunk","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.securityfocus.com/bid/92990","name":"http://www.securityfocus.com/bid/92990","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory","VDB Entry"],"title":"Splunk Enterprise and Splunk Lite CVE-2016-4856 HTML Injection Vulnerability","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"https://www.cve.org/CVERecord?id=CVE-2016-4856","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2016-4856","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"Splunk Inc.","product":"Splunk Enterprise","version":"affected 6.3.x prior to 6.3.5","platforms":[]},{"source":"CNA","vendor":"Splunk Inc.","product":"Splunk Light","version":"affected 6.3.x prior to 6.3.5","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2016","cve_id":"4856","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"splunk","cpe5":"splunk","cpe6":"6.3.0","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"enterprise","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2016","cve_id":"4856","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"splunk","cpe5":"splunk","cpe6":"6.3.0","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"light","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2016","cve_id":"4856","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"splunk","cpe5":"splunk","cpe6":"6.3.1","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"enterprise","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2016","cve_id":"4856","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"splunk","cpe5":"splunk","cpe6":"6.3.1","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"light","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2016","cve_id":"4856","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"splunk","cpe5":"splunk","cpe6":"6.3.2","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"enterprise","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2016","cve_id":"4856","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"splunk","cpe5":"splunk","cpe6":"6.3.2","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"light","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2016","cve_id":"4856","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"splunk","cpe5":"splunk","cpe6":"6.3.3","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"enterprise","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2016","cve_id":"4856","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"splunk","cpe5":"splunk","cpe6":"6.3.3","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"light","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2016","cve_id":"4856","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"splunk","cpe5":"splunk","cpe6":"6.3.4","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"enterprise","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2016","cve_id":"4856","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"splunk","cpe5":"splunk","cpe6":"6.3.4","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"light","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-06T00:46:38.427Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"https://www.splunk.com/view/SP-CAAAPN9"},{"name":"JVN#71462075","tags":["third-party-advisory","x_refsource_JVN","x_transferred"],"url":"https://jvn.jp/en/jp/JVN71462075/index.html"},{"name":"92990","tags":["vdb-entry","x_refsource_BID","x_transferred"],"url":"http://www.securityfocus.com/bid/92990"}],"title":"CVE Program Container"}],"cna":{"affected":[{"product":"Splunk Enterprise","vendor":"Splunk Inc.","versions":[{"status":"affected","version":"6.3.x prior to 6.3.5"}]},{"product":"Splunk Light","vendor":"Splunk Inc.","versions":[{"status":"affected","version":"6.3.x prior to 6.3.5"}]}],"datePublic":"2016-06-06T00:00:00.000Z","descriptions":[{"lang":"en","value":"Cross-site scripting vulnerability in Splunk Enterprise 6.3.x prior to 6.3.5 and Splunk Light 6.3.x prior to 6.3.5 allows attacker with administrator rights to inject arbitrary web script or HTML via unspecified vectors."}],"problemTypes":[{"descriptions":[{"description":"Cross-site scripting","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2017-05-15T09:57:01.000Z","orgId":"ede6fdc4-6654-4307-a26d-3331c018e2ce","shortName":"jpcert"},"references":[{"tags":["x_refsource_CONFIRM"],"url":"https://www.splunk.com/view/SP-CAAAPN9"},{"name":"JVN#71462075","tags":["third-party-advisory","x_refsource_JVN"],"url":"https://jvn.jp/en/jp/JVN71462075/index.html"},{"name":"92990","tags":["vdb-entry","x_refsource_BID"],"url":"http://www.securityfocus.com/bid/92990"}],"x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"vultures@jpcert.or.jp","ID":"CVE-2016-4856","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"Splunk Enterprise","version":{"version_data":[{"version_value":"6.3.x prior to 6.3.5"}]}},{"product_name":"Splunk Light","version":{"version_data":[{"version_value":"6.3.x prior to 6.3.5"}]}}]},"vendor_name":"Splunk Inc."}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"Cross-site scripting vulnerability in Splunk Enterprise 6.3.x prior to 6.3.5 and Splunk Light 6.3.x prior to 6.3.5 allows attacker with administrator rights to inject arbitrary web script or HTML via unspecified vectors."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"Cross-site scripting"}]}]},"references":{"reference_data":[{"name":"https://www.splunk.com/view/SP-CAAAPN9","refsource":"CONFIRM","url":"https://www.splunk.com/view/SP-CAAAPN9"},{"name":"JVN#71462075","refsource":"JVN","url":"https://jvn.jp/en/jp/JVN71462075/index.html"},{"name":"92990","refsource":"BID","url":"http://www.securityfocus.com/bid/92990"}]}}}},"cveMetadata":{"assignerOrgId":"ede6fdc4-6654-4307-a26d-3331c018e2ce","assignerShortName":"jpcert","cveId":"CVE-2016-4856","datePublished":"2017-05-12T18:00:00.000Z","dateReserved":"2016-05-17T00:00:00.000Z","dateUpdated":"2024-08-06T00:46:38.427Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2017-05-12 18:29:00","lastModifiedDate":"2025-04-20 01:37:25","problem_types":["CWE-79","Cross-site scripting"],"metrics":{"cvssMetricV30":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N","baseScore":4.8,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"HIGH","userInteraction":"REQUIRED","scope":"CHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":1.7,"impactScore":2.7}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:M/Au:S/C:N/I:P/A:N","baseScore":3.5,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"SINGLE","confidentialityImpact":"NONE","integrityImpact":"PARTIAL","availabilityImpact":"NONE"},"baseSeverity":"LOW","exploitabilityScore":6.8,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":true}]},"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:splunk:splunk:6.3.0:*:*:*:enterprise:*:*:*","matchCriteriaId":"017E3E44-C062-463F-B9D3-75BA57992C91"},{"vulnerable":true,"criteria":"cpe:2.3:a:splunk:splunk:6.3.0:*:*:*:light:*:*:*","matchCriteriaId":"0C40A2F1-343B-4C15-9C8D-9EEB3F97090B"},{"vulnerable":true,"criteria":"cpe:2.3:a:splunk:splunk:6.3.1:*:*:*:enterprise:*:*:*","matchCriteriaId":"A2BB5352-F0AF-4578-979A-7E7D3259A94A"},{"vulnerable":true,"criteria":"cpe:2.3:a:splunk:splunk:6.3.1:*:*:*:light:*:*:*","matchCriteriaId":"66AB7DB5-080E-4AC4-9FFC-0562F347C90A"},{"vulnerable":true,"criteria":"cpe:2.3:a:splunk:splunk:6.3.2:*:*:*:enterprise:*:*:*","matchCriteriaId":"011F96AC-580A-4798-82F9-5D7CF80505DF"},{"vulnerable":true,"criteria":"cpe:2.3:a:splunk:splunk:6.3.2:*:*:*:light:*:*:*","matchCriteriaId":"15DA440A-5737-48E0-9B6E-53EE25508E91"},{"vulnerable":true,"criteria":"cpe:2.3:a:splunk:splunk:6.3.3:*:*:*:enterprise:*:*:*","matchCriteriaId":"8B2CE702-BB9A-426C-ADE1-6CC0CD96A2CF"},{"vulnerable":true,"criteria":"cpe:2.3:a:splunk:splunk:6.3.3:*:*:*:light:*:*:*","matchCriteriaId":"8E2A8951-4D56-499A-8DDC-B593B436CA31"},{"vulnerable":true,"criteria":"cpe:2.3:a:splunk:splunk:6.3.4:*:*:*:enterprise:*:*:*","matchCriteriaId":"51ABD86F-DD27-43D6-AC0C-BE8E7B5A6308"},{"vulnerable":true,"criteria":"cpe:2.3:a:splunk:splunk:6.3.4:*:*:*:light:*:*:*","matchCriteriaId":"4C095802-6061-41ED-BACC-2B6AF6B42A93"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2016","CveId":"4856","Ordinal":"1","Title":"CVE-2016-4856","CVE":"CVE-2016-4856","Year":"2016"},"notes":[{"CveYear":"2016","CveId":"4856","Ordinal":"1","NoteData":"Cross-site scripting vulnerability in Splunk Enterprise 6.3.x prior to 6.3.5 and Splunk Light 6.3.x prior to 6.3.5 allows attacker with administrator rights to inject arbitrary web script or HTML via unspecified vectors.","Type":"Description","Title":"CVE-2016-4856"},{"CveYear":"2016","CveId":"4856","Ordinal":"2","NoteData":"2017-05-12","Type":"Other","Title":"Published"},{"CveYear":"2016","CveId":"4856","Ordinal":"3","NoteData":"2017-05-15","Type":"Other","Title":"Modified"}]}}}