QID 730679
QID 730679: Splunk Enterprise Denial of Service (DoS) Vulnerability (SVD-2022-1112)
Splunk captures, indexes, and correlates real-time data in a searchable repository from which it can generate graphs, reports, alerts, dashboards, and visualizations.
CVE-2022-43572: In Splunk Enterprise sending a malformed file through the Splunk-to-Splunk (S2S) or HTTP Event Collector (HEC) protocols to an indexer results in a blockage or denial-of-service preventing further indexing.
Affected Versions:
Splunk Enterprise versions 8.1.x prior to 8.1.12
Splunk Enterprise versions 8.2.x prior to 8.2.9
Splunk Enterprise versions 9.0.x prior to 9.0.2
QID Detection Logic:(Unauthenticated)
This QID checks for vulnerable versions of Splunk Enterprise by making a request to the account/login/ URL.
Successful exploitation of these vulnerability may allow an unauthenticated attacker to cause denial of service and unavailability of splunk services.
CVEs related to QID 730679
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| SVD-2022-1112 |
|