Splunk

Splunk

282 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS -
  • Veröffentlicht 07.10.2026 20:46:39
  • Zuletzt bearbeitet 07.10.2026 21:17:20

Improper Neutralization. Splunk addressed multiple internally identified vulnerabilities in Splunk Enterprise versions 10.4.3, 10.2.7, 10.0.10, and 9.4.15. The vulnerabilities are grouped by Common Weakness Enumeration (CWE), with one Common Vulnerab...

  • EPSS -
  • Veröffentlicht 07.10.2026 20:46:39
  • Zuletzt bearbeitet 07.10.2026 21:17:20

Improper Adherence to Coding Standards. Splunk addressed multiple internally identified vulnerabilities in Splunk Enterprise versions 10.4.3, 10.2.7, 10.0.10, and 9.4.15. The vulnerabilities are grouped by Common Weakness Enumeration (CWE), with one ...

  • EPSS -
  • Veröffentlicht 07.10.2026 20:46:38
  • Zuletzt bearbeitet 07.10.2026 21:17:19

Improper Control of a Resource Through its Lifetime. Splunk addressed multiple internally identified vulnerabilities in Splunk Enterprise versions 10.4.3, 10.2.7, 10.0.10, and 9.4.15. The vulnerabilities are grouped by Common Weakness Enumeration (CW...

  • EPSS -
  • Veröffentlicht 07.10.2026 20:46:38
  • Zuletzt bearbeitet 07.10.2026 21:17:19

Protection Mechanism Failure. Splunk addressed multiple internally identified vulnerabilities in Splunk Enterprise versions 10.4.3, 10.2.7, 10.0.10, and 9.4.15. The vulnerabilities are grouped by Common Weakness Enumeration (CWE), with one Common Vul...

  • EPSS -
  • Veröffentlicht 07.10.2026 20:46:37
  • Zuletzt bearbeitet 07.10.2026 21:17:19

In Splunk Enterprise versions below 10.4.3, 10.2.7, 10.0.10, and 9.4.15, and Splunk Secure Gateway versions below 3.10.11, 3.9.25, and 3.8.72, an authenticated user who does not hold the "admin" or "sc_admin" Splunk roles could modify Splunk Secure G...

  • EPSS -
  • Veröffentlicht 07.10.2026 20:46:37
  • Zuletzt bearbeitet 07.10.2026 21:17:19

Improper Access Control. Splunk addressed multiple internally identified vulnerabilities in Splunk Enterprise versions 10.4.3, 10.2.7, 10.0.10, and 9.4.15. The vulnerabilities are grouped by Common Weakness Enumeration (CWE), with one Common Vulnerab...

  • EPSS -
  • Veröffentlicht 07.10.2026 20:46:36
  • Zuletzt bearbeitet 07.10.2026 21:17:19

In Splunk Enterprise versions below 10.4.3, 10.2.7, and 10.0.10, a user that holds a role with the edit_spl2_module_permissions capability could use the affected Representational State Transfer (REST) API to access permission grants for SPL2 modules ...

  • EPSS -
  • Veröffentlicht 07.10.2026 20:46:36
  • Zuletzt bearbeitet 07.10.2026 21:17:19

In Splunk Enterprise versions below 10.4.3, 10.2.7, 10.0.10, and 9.4.15, a user that holds a role with the run_collect capability could use the collect Search Processing Language (SPL) command to write events to internal indexes outside the index acc...

  • EPSS -
  • Veröffentlicht 07.10.2026 20:46:35
  • Zuletzt bearbeitet 07.10.2026 21:17:18

In Splunk Enterprise versions below 10.4.3, 10.2.7, and 10.0.10, a low-privileged user that does not hold the "admin" or "power" Splunk roles could retrieve original source code for the Discover Splunk Observability Cloud app through Splunk Web. The ...

  • EPSS -
  • Veröffentlicht 07.10.2026 20:46:35
  • Zuletzt bearbeitet 07.10.2026 21:17:18

In Splunk Enterprise versions below 10.4.3, 10.2.7, 10.0.10, and 9.4.15, a user that holds a role with the edit_user capability could create a native Splunk username that ends with a period. The vulnerability is possible because username validation d...