Splunk Enterprise CVE-2017-17067 Multiple Security Bypass Vulnerabilities
BID:102005
Info
Splunk Enterprise CVE-2017-17067 Multiple Security Bypass Vulnerabilities
| Bugtraq ID: | 102005 |
| Class: | Input Validation Error |
| CVE: |
CVE-2017-17067 |
| Remote: | Yes |
| Local: | No |
| Published: | Nov 14 2017 12:00AM |
| Updated: | Dec 19 2017 10:01PM |
| Credit: | Jacob Honoroff |
| Vulnerable: |
Splunk Splunk Enterprise 6.6.3 Splunk Splunk Enterprise 6.6.2 Splunk Splunk Enterprise 6.6.1 Splunk Splunk Enterprise 6.6 Splunk Splunk Enterprise 6.5.5 Splunk Splunk Enterprise 6.5.4 Splunk Splunk Enterprise 6.5.3 Splunk Splunk Enterprise 6.5.2 Splunk Splunk Enterprise 6.4.8 Splunk Splunk Enterprise 6.4.7 Splunk Splunk Enterprise 6.4.6 Splunk Splunk Enterprise 6.4.4 Splunk Splunk Enterprise 6.4.1 Splunk Splunk Enterprise 6.3.11 Splunk Splunk Enterprise 6.3.10 Splunk Splunk Enterprise 6.3.9 Splunk Splunk Enterprise 6.3.8 Splunk Splunk Enterprise 6.3.7 Splunk Splunk Enterprise 6.3.4 Splunk Splunk Enterprise 6.3.3 Splunk Splunk Enterprise 6.3.2 Splunk Splunk Enterprise 6.3.1 Splunk Splunk Enterprise 7.0.0.0 Splunk Splunk Enterprise 6.5.1 Splunk Splunk Enterprise 6.5.0 Splunk Splunk Enterprise 6.4.5 Splunk Splunk Enterprise 6.4.3 Splunk Splunk Enterprise 6.4.2 Splunk Splunk Enterprise 6.4.0 Splunk Splunk Enterprise 6.3.6 Splunk Splunk Enterprise 6.3.5 Splunk Splunk Enterprise 6.3.0 |
| Not Vulnerable: |
Splunk Splunk Enterprise 6.6.4 Splunk Splunk Enterprise 6.5.6 Splunk Splunk Enterprise 6.4.9 Splunk Splunk Enterprise 6.3.12 Splunk Splunk Enterprise 7.0.0.1 Splunk Splunk Enterprise 6.6.3.2 |
Discussion
Splunk Enterprise CVE-2017-17067 Multiple Security Bypass Vulnerabilities
Splunk Enterprise is prone to multiple security-bypass vulnerabilities.
An attacker can exploit these issues to bypass security restrictions or to impersonate arbitrary users and perform unauthorized actions. This may aid in further attacks.
Splunk Enterprise 7.0.x prior to 7.0.0.1, 6.6.x prior to 6.6.3.2, 6.5.x prior to 6.5.6, 6.4.x prior to 6.4.9, and 6.3.x prior to 6.3.12 are vulnerable.
Splunk Enterprise is prone to multiple security-bypass vulnerabilities.
An attacker can exploit these issues to bypass security restrictions or to impersonate arbitrary users and perform unauthorized actions. This may aid in further attacks.
Splunk Enterprise 7.0.x prior to 7.0.0.1, 6.6.x prior to 6.6.3.2, 6.5.x prior to 6.5.6, 6.4.x prior to 6.4.9, and 6.3.x prior to 6.3.12 are vulnerable.
Exploit / POC
Splunk Enterprise CVE-2017-17067 Multiple Security Bypass Vulnerabilities
Currently, we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Currently, we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution / Fix
Splunk Enterprise CVE-2017-17067 Multiple Security Bypass Vulnerabilities
Solution:
Updates are available. Please see the references or vendor advisory for more information.
Solution:
Updates are available. Please see the references or vendor advisory for more information.
References
Splunk Enterprise CVE-2017-17067 Multiple Security Bypass Vulnerabilities
References:
References: