Splunk

Splunk Secure Gateway

12 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.23%
  • Veröffentlicht 19.08.2026 21:34:45
  • Zuletzt bearbeitet 21.08.2026 04:18:24

In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, and Splunk Secure Gateway versions below 3.10.9, 3.9.23, and 3.8.70, a user who does not hold the "admin" or "power" Splunk roles could use crafted report notification data to ca...

  • EPSS 0.21%
  • Veröffentlicht 19.08.2026 21:34:43
  • Zuletzt bearbeitet 20.08.2026 17:19:42

In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, and Splunk Secure Gateway versions below 3.10.9, 3.9.23, and 3.8.70, a user who does not hold the "admin" or "power" Splunk roles could use Server-Side Request Forgery (SSRF) in ...

  • EPSS 0.21%
  • Veröffentlicht 19.08.2026 21:34:31
  • Zuletzt bearbeitet 20.08.2026 13:01:19

In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, and Splunk Secure Gateway versions below 3.10.9, 3.9.23, and 3.8.70, an unauthenticated user could trick a user who holds the "admin" or "sc_admin" Splunk roles into opening a cr...

  • EPSS 0.21%
  • Veröffentlicht 19.08.2026 21:34:18
  • Zuletzt bearbeitet 20.08.2026 14:27:18

In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, and Splunk Secure Gateway versions below 3.10.9, 3.9.23, and 3.8.70, a user who does not hold the "admin" or "power" Splunk roles could read Spacebridge asymmetric private keys, ...

  • EPSS 0.25%
  • Veröffentlicht 19.08.2026 21:34:16
  • Zuletzt bearbeitet 20.08.2026 14:53:07

In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, and Splunk Secure Gateway versions below 3.10.10, 3.9.24, and 3.8.71, a user who does not hold the "admin" or "power" Splunk roles could register an arbitrary companion app and c...

  • EPSS 0.22%
  • Veröffentlicht 19.08.2026 21:34:15
  • Zuletzt bearbeitet 20.08.2026 14:54:14

In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, and Splunk Secure Gateway versions below 3.10.9, 3.9.23, and 3.8.70, a user who does not hold the "admin" or "power" Splunk roles could read sensitive Security Assertion Markup L...

  • EPSS 0.25%
  • Veröffentlicht 19.08.2026 21:34:15
  • Zuletzt bearbeitet 20.08.2026 14:53:35

In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, and Splunk Secure Gateway versions below 3.10.10, 3.9.24, and 3.8.71, a user who holds a Splunk role with permissions to list storage passwords but does not hold Splunk Secure Ga...

  • EPSS 18.99%
  • Veröffentlicht 10.06.2026 17:16:00
  • Zuletzt bearbeitet 15.06.2026 17:08:59

In Splunk Enterprise versions below 10.2.4, 10.0.7, 9.4.12, and 9.3.13, Splunk Cloud Platform versions below 10.3.2512.12, 10.2.2510.14, 10.1.2507.22, and 9.3.2411.132, and Splunk Secure Gateway versions below 3.10.6, 3.9.20, and 3.8.67, a low-privil...

Medienbericht
  • EPSS 0.41%
  • Veröffentlicht 03.12.2025 17:00:55
  • Zuletzt bearbeitet 05.12.2025 17:05:57

In Splunk Enterprise versions below 10.0.2, 9.4.6, 9.3.8, and 9.2.10, and versions below 3.9.10, 3.8.58 and 3.7.28 of the Splunk Secure Gateway app on Splunk Cloud Platform, a low-privileged user that does not hold the "admin" or "power" Splunk roles...

  • EPSS 0.3%
  • Veröffentlicht 03.12.2025 17:00:36
  • Zuletzt bearbeitet 05.12.2025 18:30:13

In Splunk Enterprise versions below 10.0.2, 9.4.6, 9.3.8, and 9.2.10, and below 3.9.10, 3.8.58, and 3.7.28 of Splunk Secure Gateway app in Splunk Cloud Platform, a low-privileged user that does not hold the "admin" or "power" Splunk roles and subscri...