QID 378009
Date Published: 2023-03-29
QID 378009: Splunk Enterprise Multiple Vulnerabilities (SVD-2023-0212,SVD-2023-0210,SVD-2023-0209,SVD-2023-0205,SVD-2023-0204,SVD-2023-0203)
Splunk Enterprise captures, indexes and correlates real-time data in a searchable repository from which it can generate graphs, reports, alerts, dashboards, and visualizations.
Splunk Enterprise is affected by multiple vulnerabilities:
Affected Versions:
Splunk Enterprise 8.1.12 and lower
Splunk Enterprise 8.2.0 to 8.2.9
Splunk Enterprise 9.0.0 to 9.0.3
QID Detection Logic(Authenticated)
It checks for vulnerable version of Splunk Enterprise .
Successful exploitation of this vulnerability could lead to a security breach or could affect integrity, availability, and confidentiality.
Workaround:
If users do not log in to Splunk Web on indexers in a distributed environment, disable Splunk Web on those indexers. and the web.conf configuration specification file for more information on disabling Splunk Web.
- SVD-2023-0203 -
advisory.splunk.com/advisories/SVD-2023-0203 - SVD-2023-0204 -
advisory.splunk.com/advisories/SVD-2023-0204 - SVD-2023-0205 -
advisory.splunk.com/advisories/SVD-2023-0205 - SVD-2023-0209 -
advisory.splunk.com/advisories/SVD-2023-0209 - SVD-2023-0210 -
advisory.splunk.com/advisories/SVD-2023-0210 - SVD-2023-0212 -
advisory.splunk.com/advisories/SVD-2023-0212
CVEs related to QID 378009
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| SVD-2023-0203 |
|
||
| SVD-2023-0204 |
|
||
| SVD-2023-0205 |
|
||
| SVD-2023-0209 |
|
||
| SVD-2023-0210 |
|
||
| SVD-2023-0212 |
|