Splunk

Splunk

282 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 1.92%
  • Veröffentlicht 15.06.2022 17:15:09
  • Zuletzt bearbeitet 21.11.2024 07:05:51

In universal forwarder versions before 9.0, management services are available remotely by default. When not required, it introduces a potential exposure, but it is not a vulnerability. If exposed, we recommend each customer assess the potential sever...

  • EPSS 0.78%
  • Veröffentlicht 15.06.2022 17:15:09
  • Zuletzt bearbeitet 25.02.2026 16:16:56

In Splunk Enterprise and Universal Forwarder versions before 9.0, the Splunk command-line interface (CLI) did not validate TLS certificates while connecting to a remote Splunk platform instance by default. After updating to version 9.0, see Configur...

  • EPSS 1.28%
  • Veröffentlicht 15.06.2022 17:15:09
  • Zuletzt bearbeitet 21.11.2024 07:05:51

Splunk Enterprise deployment servers in versions before 9.0 allow unauthenticated downloading of forwarder bundles. Remediation requires you to update the deployment server to version 9.0 and Configure authentication for deployment servers and client...

  • EPSS 1.39%
  • Veröffentlicht 15.06.2022 17:15:09
  • Zuletzt bearbeitet 21.11.2024 07:05:51

Splunk Enterprise deployment servers in versions before 8.1.10.1, 8.2.6.1, and 9.0 let clients deploy forwarder bundles to other deployment clients through the deployment server. An attacker that compromised a Universal Forwarder endpoint could use t...

  • EPSS 0.76%
  • Veröffentlicht 15.06.2022 17:15:08
  • Zuletzt bearbeitet 21.11.2024 07:05:50

The httplib and urllib Python libraries that Splunk shipped with Splunk Enterprise did not validate certificates using the certificate authority (CA) certificate stores by default in Splunk Enterprise versions before 9.0 and Splunk Cloud Platform ver...

  • EPSS 0.91%
  • Veröffentlicht 15.06.2022 17:15:08
  • Zuletzt bearbeitet 21.11.2024 07:05:50

Splunk Enterprise peers in Splunk Enterprise versions before 9.0 and Splunk Cloud Platform versions before 8.2.2203 did not validate the TLS certificates during Splunk-to-Splunk communications by default. Splunk peer communications configured properl...

  • EPSS 0.87%
  • Veröffentlicht 15.06.2022 17:15:08
  • Zuletzt bearbeitet 21.11.2024 07:05:50

Splunk Enterprise peers in Splunk Enterprise versions before 9.0 and Splunk Cloud Platform versions before 8.2.2203 did not validate the TLS certificates during Splunk-to-Splunk communications by default. Splunk peer communications configured properl...

  • EPSS 0.79%
  • Veröffentlicht 06.05.2022 17:15:08
  • Zuletzt bearbeitet 21.11.2024 05:55:59

A potential vulnerability in Splunk Enterprise's implementation of DUO MFA allows for bypassing the MFA verification in Splunk Enterprise versions before 8.1.6. The potential vulnerability impacts Splunk Enterprise instances configured to use DUO MFA...

  • EPSS 0.86%
  • Veröffentlicht 06.05.2022 17:15:08
  • Zuletzt bearbeitet 21.11.2024 06:05:54

A crafted request bypasses S2S TCP Token authentication writing arbitrary events to an index in Splunk Enterprise Indexer 8.1 versions before 8.1.5 and 8.2 versions before 8.2.1. The vulnerability impacts Indexers configured to use TCPTokens. It does...

  • EPSS 0.86%
  • Veröffentlicht 06.05.2022 17:15:08
  • Zuletzt bearbeitet 21.11.2024 06:09:41

The Splunk Enterprise REST API allows enumeration of usernames via the lockout error message. The potential vulnerability impacts Splunk Enterprise instances before 8.1.7 when configured to repress verbose login errors.