Splunk

Splunk Secure Gateway

15 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS -
  • Veröffentlicht 07.10.2026 20:46:37
  • Zuletzt bearbeitet 07.10.2026 21:17:19

In Splunk Enterprise versions below 10.4.3, 10.2.7, 10.0.10, and 9.4.15, and Splunk Secure Gateway versions below 3.10.11, 3.9.25, and 3.8.72, an authenticated user who does not hold the "admin" or "sc_admin" Splunk roles could modify Splunk Secure G...

  • EPSS -
  • Veröffentlicht 07.10.2026 20:46:33
  • Zuletzt bearbeitet 07.10.2026 21:17:18

In Splunk Enterprise versions below 10.4.3, 10.2.7, 10.0.10, and 9.4.15, a user who does not hold the "admin" or "power" Splunk roles could cause Splunk Secure Gateway to sign attacker-controlled payloads. The vulnerability is possible because Splunk...

  • EPSS -
  • Veröffentlicht 07.10.2026 20:46:29
  • Zuletzt bearbeitet 07.10.2026 21:17:17

In Splunk Enterprise versions below 10.4.3, 10.2.7, 10.0.10, and 9.4.15, and Splunk Secure Gateway versions below 3.10.11, 3.9.25, and 3.8.72, a user who does not hold the "admin" or "power" Splunk roles could access privileged Splunk Secure Gateway ...

  • EPSS 0.23%
  • Veröffentlicht 19.08.2026 21:34:45
  • Zuletzt bearbeitet 21.08.2026 19:17:12

In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, and Splunk Secure Gateway versions below 3.10.9, 3.9.23, and 3.8.70, a user who does not hold the "admin" or "power" Splunk roles could use crafted report notification data to ca...

  • EPSS 0.21%
  • Veröffentlicht 19.08.2026 21:34:43
  • Zuletzt bearbeitet 21.08.2026 19:17:09

In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, and Splunk Secure Gateway versions below 3.10.9, 3.9.23, and 3.8.70, a user who does not hold the "admin" or "power" Splunk roles could use Server-Side Request Forgery (SSRF) in ...

  • EPSS 0.21%
  • Veröffentlicht 19.08.2026 21:34:31
  • Zuletzt bearbeitet 26.08.2026 16:16:39

In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, and Splunk Secure Gateway versions below 3.10.9, 3.9.23, and 3.8.70, an unauthenticated user could trick a user who holds the "admin" or "sc_admin" Splunk roles into opening a cr...

  • EPSS 0.21%
  • Veröffentlicht 19.08.2026 21:34:18
  • Zuletzt bearbeitet 26.08.2026 20:18:00

In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, and Splunk Secure Gateway versions below 3.10.9, 3.9.23, and 3.8.70, a user who does not hold the "admin" or "power" Splunk roles could read Spacebridge asymmetric private keys, ...

  • EPSS 0.25%
  • Veröffentlicht 19.08.2026 21:34:16
  • Zuletzt bearbeitet 26.08.2026 16:16:38

In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, and Splunk Secure Gateway versions below 3.10.10, 3.9.24, and 3.8.71, a user who does not hold the "admin" or "power" Splunk roles could register an arbitrary companion app and c...

  • EPSS 0.22%
  • Veröffentlicht 19.08.2026 21:34:15
  • Zuletzt bearbeitet 26.08.2026 16:16:38

In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, and Splunk Secure Gateway versions below 3.10.9, 3.9.23, and 3.8.70, a user who does not hold the "admin" or "power" Splunk roles could read sensitive Security Assertion Markup L...

  • EPSS 0.25%
  • Veröffentlicht 19.08.2026 21:34:15
  • Zuletzt bearbeitet 26.08.2026 16:16:38

In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, and Splunk Secure Gateway versions below 3.10.10, 3.9.24, and 3.8.71, a user who holds a Splunk role with permissions to list storage passwords but does not hold Splunk Secure Ga...