QID 378509

Date Published: 2023-06-29

QID 378509: Splunk Enterprise Multiple Vulnerabilities (SP-CAAAPKV)

Splunk is a log monitoring and reporting tool with search capabilities.

Splunk Enterprise multiple flaws let remote users bypass security and deny service and remote authenticated users execute arbitrary code

Affected Version Prior to
Splunk Enterprise 6.3.3.4, 6.2.9. 6.1.10, 6.0.11, and 5.0.15

A remote authenticated user can access and overwrite files on the target system.
A remote authenticated user can execute arbitrary code on the target system.
A remote authenticated user can obtain potentially sensitive information on the target system.
A remote user can cause denial of service conditions. A remote user can bypass security controls on the target system.

  • CVSS V3 rated as Critical - 9.8 severity.
  • CVSS V2 rated as Critical - 10 severity.
  • Solution
    Splunk has issued an updated version 6.4 to fix vulnerabilities.
    Vendor References
    Software Advisories
    Advisory ID Software Component Link
    SP-CAAAPKV URL Logo www.splunk.com/en_us/download.html