10

CVE-2016-10126

Splunk Web in Splunk Enterprise 5.0.x before 5.0.17, 6.0.x before 6.0.13, 6.1.x before 6.1.12, 6.2.x before 6.2.12, 6.3.x before 6.3.8, and 6.4.x before 6.4.4 allows remote attackers to conduct HTTP request injection attacks and obtain sensitive REST API authentication-token information via unspecified vectors, aka SPL-128840.

Data is provided by the National Vulnerability Database (NVD)
SplunkSplunk Version5.0.0 SwEditionenterprise
SplunkSplunk Version5.0.1 SwEditionenterprise
SplunkSplunk Version5.0.2 SwEditionenterprise
SplunkSplunk Version5.0.3 SwEditionenterprise
SplunkSplunk Version5.0.4 SwEditionenterprise
SplunkSplunk Version5.0.5 SwEditionenterprise
SplunkSplunk Version5.0.6 SwEditionenterprise
SplunkSplunk Version5.0.7 SwEditionenterprise
SplunkSplunk Version5.0.8 SwEditionenterprise
SplunkSplunk Version5.0.9 SwEditionenterprise
SplunkSplunk Version5.0.10 SwEditionenterprise
SplunkSplunk Version5.0.11 SwEditionenterprise
SplunkSplunk Version5.0.12 SwEditionenterprise
SplunkSplunk Version5.0.13 SwEditionenterprise
SplunkSplunk Version5.0.14 SwEditionenterprise
SplunkSplunk Version5.0.15 SwEditionenterprise
SplunkSplunk Version5.0.16 SwEditionenterprise
SplunkSplunk Version6.0.0 SwEditionenterprise
SplunkSplunk Version6.0.1 SwEditionenterprise
SplunkSplunk Version6.0.2 SwEditionenterprise
SplunkSplunk Version6.0.3 SwEditionenterprise
SplunkSplunk Version6.0.4 SwEditionenterprise
SplunkSplunk Version6.0.5 SwEditionenterprise
SplunkSplunk Version6.0.6 SwEditionenterprise
SplunkSplunk Version6.0.7 SwEditionenterprise
SplunkSplunk Version6.0.8 SwEditionenterprise
SplunkSplunk Version6.0.9 SwEditionenterprise
SplunkSplunk Version6.0.10 SwEditionenterprise
SplunkSplunk Version6.0.11 SwEditionenterprise
SplunkSplunk Version6.0.12 SwEditionenterprise
SplunkSplunk Version6.1.0 SwEditionenterprise
SplunkSplunk Version6.1.1 SwEditionenterprise
SplunkSplunk Version6.1.2 SwEditionenterprise
SplunkSplunk Version6.1.3 SwEditionenterprise
SplunkSplunk Version6.1.4 SwEditionenterprise
SplunkSplunk Version6.1.5 SwEditionenterprise
SplunkSplunk Version6.1.6 SwEditionenterprise
SplunkSplunk Version6.1.7 SwEditionenterprise
SplunkSplunk Version6.1.8 SwEditionenterprise
SplunkSplunk Version6.1.9 SwEditionenterprise
SplunkSplunk Version6.1.10 SwEditionenterprise
SplunkSplunk Version6.1.11 SwEditionenterprise
SplunkSplunk Version6.2.0 SwEditionenterprise
SplunkSplunk Version6.2.1 SwEditionenterprise
SplunkSplunk Version6.2.2 SwEditionenterprise
SplunkSplunk Version6.2.3 SwEditionenterprise
SplunkSplunk Version6.2.4 SwEditionenterprise
SplunkSplunk Version6.2.5 SwEditionenterprise
SplunkSplunk Version6.2.6 SwEditionenterprise
SplunkSplunk Version6.2.7 SwEditionenterprise
SplunkSplunk Version6.2.8 SwEditionenterprise
SplunkSplunk Version6.2.9 SwEditionenterprise
SplunkSplunk Version6.2.10 SwEditionenterprise
SplunkSplunk Version6.2.11 SwEditionenterprise
SplunkSplunk Version6.3.0 SwEditionenterprise
SplunkSplunk Version6.3.1 SwEditionenterprise
SplunkSplunk Version6.3.2 SwEditionenterprise
SplunkSplunk Version6.3.3 SwEditionenterprise
SplunkSplunk Version6.3.4 SwEditionenterprise
SplunkSplunk Version6.3.5 SwEditionenterprise
SplunkSplunk Version6.3.6 SwEditionenterprise
SplunkSplunk Version6.3.7 SwEditionenterprise
SplunkSplunk Version6.4.0 SwEditionenterprise
SplunkSplunk Version6.4.1 SwEditionenterprise
SplunkSplunk Version6.4.2 SwEditionenterprise
SplunkSplunk Version6.4.3 SwEditionenterprise
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 1.37% 0.796
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 9.8 3.9 5.9
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvd@nist.gov 10 10 10
AV:N/AC:L/Au:N/C:C/I:C/A:C