Splunk

Splunk

282 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS -
  • Veröffentlicht 07.10.2026 20:46:34
  • Zuletzt bearbeitet 07.10.2026 21:17:18

In Splunk Enterprise versions below 10.4.3, 10.2.7, and 10.0.10, a user that holds a role with the read_o11y_content capability could redirect an outbound request from Splunk App for Splunk Observability Cloud through the Representational State Trans...

  • EPSS -
  • Veröffentlicht 07.10.2026 20:46:34
  • Zuletzt bearbeitet 07.10.2026 21:17:18

In Splunk Enterprise versions below 10.4.3, 10.2.7, 10.0.10, and 9.4.15, a user who does not hold the "admin" or "power" Splunk roles could access search query text and job metadata for jobs that belong to other users, including job identifiers, disp...

  • EPSS -
  • Veröffentlicht 07.10.2026 20:46:33
  • Zuletzt bearbeitet 07.10.2026 21:17:18

In Splunk Enterprise versions below 10.4.3, 10.2.7, 10.0.10, and 9.4.15, a user that holds a role with the run_collect capability could use the collect Search Processing Language (SPL) command to add attacker-controlled content to system-level messag...

  • EPSS -
  • Veröffentlicht 07.10.2026 20:46:32
  • Zuletzt bearbeitet 07.10.2026 21:17:17

In Splunk Enterprise versions below 10.4.3, a user that holds a role with the list_spl2_modules capability could use SQL injection in SPL2 module filtering to access all relevant data available through the affected Representational State Transfer (RE...

  • EPSS -
  • Veröffentlicht 07.10.2026 20:46:32
  • Zuletzt bearbeitet 07.10.2026 21:17:18

In Splunk Enterprise versions below 10.4.3, 10.2.7, and 10.0.10, a low-privileged user that does not hold the "admin" or "power" Splunk roles could cause a denial of service against a Representational State Transfer (REST) API endpoint in the Discove...

  • EPSS -
  • Veröffentlicht 07.10.2026 20:46:31
  • Zuletzt bearbeitet 07.10.2026 21:17:17

In Splunk Enterprise versions below 10.4.3, 10.2.7, 10.0.10, and 9.4.15, a user who does not hold the "admin" or "power" Splunk roles could use a user-controlled job identifier to access substantially all search job information from jobs that belong ...

  • EPSS -
  • Veröffentlicht 07.10.2026 20:46:30
  • Zuletzt bearbeitet 07.10.2026 21:17:17

In Splunk Enterprise versions below 10.4.3, 10.2.7, and 10.0.10, a user that holds a role with the read_o11y_content capability could inject forged entries into the app log through the Representational State Transfer (REST) API. The vulnerability is ...

  • EPSS -
  • Veröffentlicht 07.10.2026 20:46:28
  • Zuletzt bearbeitet 07.10.2026 21:17:17

In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.10, and 9.4.15, a user who does not hold the "admin" or "power" Splunk roles could create or edit scripted lookup definitions through raw configuration endpoints. The vulnerability is possible ...

  • EPSS 0.24%
  • Veröffentlicht 19.08.2026 21:34:47
  • Zuletzt bearbeitet 21.08.2026 19:19:17

In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, a user who does not hold the "admin" or "power" Splunk roles could affect system integrity and availability by sending a crafted Representational State Transfer (REST) API reques...

  • EPSS 0.35%
  • Veröffentlicht 19.08.2026 21:34:47
  • Zuletzt bearbeitet 26.08.2026 16:16:41

In Splunk Enterprise 10.4 versions below 10.4.2, an unauthenticated user could retrieve the information contained in Edge Processor pipeline configurations through a Representational State Transfer (REST) API endpoint when Edge Processor is turned on...