CVE-2024-45741
- EPSS 0.18%
- Published 14.10.2024 17:15:13
- Last modified 17.10.2024 13:12:54
In Splunk Enterprise versions below 9.2.3 and 9.1.6 and Splunk Cloud Platform versions below 9.2.2403.108 and 9.1.2312.205, a low-privileged user that does not hold the "admin" or "power" Splunk roles could create a malicious payload through a custom...
CVE-2024-45735
- EPSS 0.03%
- Published 14.10.2024 17:15:12
- Last modified 16.10.2024 22:20:32
In Splunk Enterprise versions below 9.2.3 and 9.1.6, and Splunk Secure Gateway versions on Splunk Cloud Platform versions below 3.4.259, 3.6.17, and 3.7.0, a low-privileged user that does not hold the "admin" or "power" Splunk roles can see App Key V...
CVE-2024-45736
- EPSS 0.08%
- Published 14.10.2024 17:15:12
- Last modified 16.10.2024 22:19:44
In Splunk Enterprise versions below 9.3.1, 9.2.3, and 9.1.6 and Splunk Cloud Platform versions below 9.2.2403.107, 9.1.2312.204, and 9.1.2312.111, a low-privileged user that does not hold the "admin" or "power" Splunk roles could craft a search query...
CVE-2024-45737
- EPSS 0.02%
- Published 14.10.2024 17:15:12
- Last modified 16.10.2024 22:18:17
In Splunk Enterprise versions below 9.3.1, 9.2.3, and 9.1.6 and Splunk Cloud Platform versions below 9.2.2403.108, and 9.1.2312.204, a low-privileged user that does not hold the "admin" or "power" Splunk roles could change the maintenance mode state ...
CVE-2024-45738
- EPSS 0.05%
- Published 14.10.2024 17:15:12
- Last modified 17.10.2024 13:17:37
In Splunk Enterprise versions below 9.3.1, 9.2.3, and 9.1.6, the software potentially exposes sensitive HTTP parameters to the `_internal` index. This exposure could happen if you configure the Splunk Enterprise `REST_Calls` log channel at the DEBUG ...
CVE-2024-45739
- EPSS 0.05%
- Published 14.10.2024 17:15:12
- Last modified 17.10.2024 13:16:36
In Splunk Enterprise versions below 9.3.1, 9.2.3, and 9.1.6, the software potentially exposes plaintext passwords for local native authentication Splunk users. This exposure could happen when you configure the Splunk Enterprise AdminManager log chann...
- EPSS 0.07%
- Published 14.10.2024 17:15:11
- Last modified 17.10.2024 13:09:33
In Splunk Enterprise for Windows versions below 9.3.1, 9.2.3, and 9.1.6, a low-privileged user that does not hold the "admin" or "power" Splunk roles could write a file to the Windows system root directory, which has a default location in the Windows...
CVE-2024-45732
- EPSS 0.04%
- Published 14.10.2024 17:15:11
- Last modified 17.10.2024 13:03:52
In Splunk Enterprise versions below 9.3.1, and 9.2.0 versions below 9.2.3, and Splunk Cloud Platform versions below 9.2.2403.103, 9.1.2312.200, 9.1.2312.110 and 9.1.2308.208, a low-privileged user that does not hold the "admin" or "power" Splunk role...
CVE-2024-45733
- EPSS 0.83%
- Published 14.10.2024 17:15:11
- Last modified 16.10.2024 22:26:12
In Splunk Enterprise for Windows versions below 9.2.3 and 9.1.6, a low-privileged user that does not hold the "admin" or "power" Splunk roles could perform a Remote Code Execution (RCE) due to an insecure session storage configuration.
CVE-2024-45734
- EPSS 0.03%
- Published 14.10.2024 17:15:11
- Last modified 16.10.2024 22:20:57
In Splunk Enterprise versions 9.3.0, 9.2.3, and 9.1.6, a low-privileged user that does not hold the "admin" or "power" Splunk roles could view images on the machine that runs Splunk Enterprise by using the PDF export feature in Splunk classic dashboa...