QID 730314
Date Published: 2021-12-28
QID 730314: Splunk Enterprise and Light Denial of Service (DoS) Vulnerability (SP-CAAAPW8) (SPL-130279)
Splunk captures, indexes, and correlates real-time data in a searchable repository from which it can generate graphs, reports, alerts, dashboards, and visualizations.
CVE-2017-5880: Allows remote authenticated users to cause a denial of service (daemon crash) via a crafted GET request
Affected Versions:
Splunk Enterprise versions 6.5.x before 6.5.2
Splunk Enterprise versions 6.4.x before 6.4.5
Splunk Enterprise versions 6.3.x before 6.3.9
Splunk Enterprise versions 6.2.x before 6.2.13
Splunk Enterprise versions 6.1.x before 6.1.12
Splunk Enterprise versions 6.0.x before 6.0.13
Splunk Enterprise versions 5.0.x before 5.0.17
Splunk Light versions prior to 6.5.2
QID Detection Logic:(Unauthenticated)
This QID checks for vulnerable versions of Splunk Enterprise and Light by making a request to the account/login/ URL.
Successful exploitation of this vulnerability may allow a remote authenticated attacker to crash splunk web service.
- SP-CAAAPW8 (SPL-130279) -
www.splunk.com/en_us/product-security/announcements-archive/SP-CAAAPW8.html
CVEs related to QID 730314
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| SP-CAAAPW8 (SPL-130279) |
|