QID 378004

Date Published: 2023-03-27

QID 378004: Splunk Enterprise Multiple Vulnerabilities (SVD-2023-0215,SVD-2023-0211,SVD-2023-0208)

Splunk Enterprise captures, indexes and correlates real-time data in a searchable repository from which it can generate graphs, reports, alerts, dashboards, and visualizations.

Splunk Enterprise is affected by multiple vulnerabilities:

Affected Versions:
Splunk Enterprise 8.1.12 and lower
Splunk Enterprise 8.2.0 to 8.2.9
Splunk Enterprise 9.0.0 to 9.0.3

QID Detection Logic(Authenticated)
It checks for vulnerable version of Splunk Enterprise .

Successful exploitation of this vulnerability could lead to a security breach or could affect integrity, availability, and confidentiality.

  • CVSS V3 rated as Critical - 8.8 severity.
  • CVSS V2 rated as High - 8 severity.
  • Solution
    Vendor has released updated versions to fix these vulnerabilities. Please refer SVD-2023-0215 SVD-2023-0211 SVD-2023-0208 for more details.

    Software Advisories
    Advisory ID Software Component Link
    SVD-2023-0208 URL Logo advisory.splunk.com/advisories/SVD-2023-0208
    SVD-2023-0211 URL Logo advisory.splunk.com/advisories/SVD-2023-0211
    SVD-2023-0215 URL Logo advisory.splunk.com/advisories/SVD-2023-0215