Splunk

Soar

17 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.21%
  • Veröffentlicht 19.08.2026 21:34:51
  • Zuletzt bearbeitet 20.08.2026 17:19:44

In Splunk SOAR versions below 8.6.0, an authenticated user with no role assigned could use the /rest/health endpoint to gather system and cluster telemetry that should be restricted to administrative or support users. The vulnerability is a missing a...

  • EPSS 0.36%
  • Veröffentlicht 19.08.2026 21:34:50
  • Zuletzt bearbeitet 20.08.2026 17:19:44

In Splunk SOAR versions below 8.6.0, a user who holds the Administrator role could use path traversal in the Universal Forwarder installer's archive extraction to write files outside the intended installation directory. The vulnerability is possible ...

  • EPSS 0.36%
  • Veröffentlicht 19.08.2026 21:34:49
  • Zuletzt bearbeitet 20.08.2026 17:19:44

In Splunk SOAR versions below 8.6.0, a user with app-install privileges could use path traversal during app installation to write files outside the intended temporary directory. The vulnerability is a path traversal in the archive extraction routine,...

  • EPSS 0.32%
  • Veröffentlicht 19.08.2026 21:34:49
  • Zuletzt bearbeitet 20.08.2026 17:19:44

In Splunk SOAR versions below 8.6.0, an authenticated user with no role assigned could submit a crafted file path to the Representational State Transfer (REST) API and execute arbitrary code. The vulnerability is possible because the REST API does no...

  • EPSS 0.36%
  • Veröffentlicht 19.08.2026 21:34:48
  • Zuletzt bearbeitet 21.08.2026 04:18:24

In Splunk SOAR versions below 8.6.0, an unauthenticated user could spoof the source IP address in a crafted request to an Automation Broker notification endpoint and execute arbitrary code on the Splunk SOAR host. The vulnerability is possible becaus...

  • EPSS 0.2%
  • Veröffentlicht 10.06.2026 17:16:20
  • Zuletzt bearbeitet 10.06.2026 18:36:19

In Splunk SOAR (Security Orchestration, Automation, and Response) versions below 8.5.0, an unauthenticated attacker could inject American National Standards Institute (ANSI) escape codes into SOAR application log files through specially crafted HTTP ...

  • EPSS 0.29%
  • Veröffentlicht 31.07.2023 17:15:10
  • Zuletzt bearbeitet 10.12.2024 18:15:25

Splunk SOAR versions lower than 6.1.0 are indirectly affected by a potential vulnerability accessed through the user’s terminal. A third party can send Splunk SOAR a maliciously crafted web request containing special ANSI characters to cause log file...