CVE-2024-45741
- EPSS 0.18%
- Veröffentlicht 14.10.2024 17:15:13
- Zuletzt bearbeitet 17.10.2024 13:12:54
In Splunk Enterprise versions below 9.2.3 and 9.1.6 and Splunk Cloud Platform versions below 9.2.2403.108 and 9.1.2312.205, a low-privileged user that does not hold the "admin" or "power" Splunk roles could create a malicious payload through a custom...
CVE-2024-45735
- EPSS 0.03%
- Veröffentlicht 14.10.2024 17:15:12
- Zuletzt bearbeitet 16.10.2024 22:20:32
In Splunk Enterprise versions below 9.2.3 and 9.1.6, and Splunk Secure Gateway versions on Splunk Cloud Platform versions below 3.4.259, 3.6.17, and 3.7.0, a low-privileged user that does not hold the "admin" or "power" Splunk roles can see App Key V...
CVE-2024-45736
- EPSS 0.08%
- Veröffentlicht 14.10.2024 17:15:12
- Zuletzt bearbeitet 16.10.2024 22:19:44
In Splunk Enterprise versions below 9.3.1, 9.2.3, and 9.1.6 and Splunk Cloud Platform versions below 9.2.2403.107, 9.1.2312.204, and 9.1.2312.111, a low-privileged user that does not hold the "admin" or "power" Splunk roles could craft a search query...
CVE-2024-45737
- EPSS 0.02%
- Veröffentlicht 14.10.2024 17:15:12
- Zuletzt bearbeitet 16.10.2024 22:18:17
In Splunk Enterprise versions below 9.3.1, 9.2.3, and 9.1.6 and Splunk Cloud Platform versions below 9.2.2403.108, and 9.1.2312.204, a low-privileged user that does not hold the "admin" or "power" Splunk roles could change the maintenance mode state ...
CVE-2024-45738
- EPSS 0.05%
- Veröffentlicht 14.10.2024 17:15:12
- Zuletzt bearbeitet 17.10.2024 13:17:37
In Splunk Enterprise versions below 9.3.1, 9.2.3, and 9.1.6, the software potentially exposes sensitive HTTP parameters to the `_internal` index. This exposure could happen if you configure the Splunk Enterprise `REST_Calls` log channel at the DEBUG ...
CVE-2024-45739
- EPSS 0.05%
- Veröffentlicht 14.10.2024 17:15:12
- Zuletzt bearbeitet 17.10.2024 13:16:36
In Splunk Enterprise versions below 9.3.1, 9.2.3, and 9.1.6, the software potentially exposes plaintext passwords for local native authentication Splunk users. This exposure could happen when you configure the Splunk Enterprise AdminManager log chann...
- EPSS 0.07%
- Veröffentlicht 14.10.2024 17:15:11
- Zuletzt bearbeitet 17.10.2024 13:09:33
In Splunk Enterprise for Windows versions below 9.3.1, 9.2.3, and 9.1.6, a low-privileged user that does not hold the "admin" or "power" Splunk roles could write a file to the Windows system root directory, which has a default location in the Windows...
CVE-2024-45732
- EPSS 0.04%
- Veröffentlicht 14.10.2024 17:15:11
- Zuletzt bearbeitet 17.10.2024 13:03:52
In Splunk Enterprise versions below 9.3.1, and 9.2.0 versions below 9.2.3, and Splunk Cloud Platform versions below 9.2.2403.103, 9.1.2312.200, 9.1.2312.110 and 9.1.2308.208, a low-privileged user that does not hold the "admin" or "power" Splunk role...
CVE-2024-45733
- EPSS 0.83%
- Veröffentlicht 14.10.2024 17:15:11
- Zuletzt bearbeitet 16.10.2024 22:26:12
In Splunk Enterprise for Windows versions below 9.2.3 and 9.1.6, a low-privileged user that does not hold the "admin" or "power" Splunk roles could perform a Remote Code Execution (RCE) due to an insecure session storage configuration.
CVE-2024-45734
- EPSS 0.03%
- Veröffentlicht 14.10.2024 17:15:11
- Zuletzt bearbeitet 16.10.2024 22:20:57
In Splunk Enterprise versions 9.3.0, 9.2.3, and 9.1.6, a low-privileged user that does not hold the "admin" or "power" Splunk roles could view images on the machine that runs Splunk Enterprise by using the PDF export feature in Splunk classic dashboa...