CVE-2025-20385
- EPSS 0.03%
- Veröffentlicht 03.12.2025 17:00:29
- Zuletzt bearbeitet 05.12.2025 18:13:10
In Splunk Enterprise versions below 10.0.2, 9.4.6, 9.3.8, and 9.2.10, and Splunk Cloud Platform versions below 10.1.2507.6, 10.0.2503.7, and 9.3.2411.117, a user who holds a role with a high privilege capability `admin_all_objects` could craft a mali...
CVE-2025-20382
- EPSS 0.03%
- Veröffentlicht 03.12.2025 17:00:21
- Zuletzt bearbeitet 05.12.2025 18:33:45
In Splunk Enterprise versions below 10.0.2, 9.4.6, 9.3.8, and 9.2.10, and Splunk Cloud Platform versions below 10.1.2507.10, 10.0.2503.8, and 9.3.2411.120, a low-privileged user that does not hold the "admin" or "power" Splunk roles could create a vi...
CVE-2025-20379
- EPSS 0.03%
- Veröffentlicht 12.11.2025 17:23:00
- Zuletzt bearbeitet 03.12.2025 21:41:26
In Splunk Enterprise versions below 10.0.1, 9.4.5, 9.3.7, and 9.2.9 and Splunk Cloud Platform versions below 9.3.2411.116, 9.3.2408.124, 10.0.2503.5 and 10.1.2507.1, a low-privileged user that does not hold the “admin“ or “power“ Splunk roles could r...
CVE-2025-20378
- EPSS 0.05%
- Veröffentlicht 12.11.2025 17:22:56
- Zuletzt bearbeitet 03.12.2025 21:43:31
In Splunk Enterprise versions below 10.0.1, 9.4.5, 9.3.7, 9.2.9, and Splunk Cloud Platform versions below 10.0.2503.5, 9.3.2411.111, and 9.3.2408.121, an unauthenticated attacker could craft a malicious URL using the `return_to` parameter of the Splu...
CVE-2025-20369
- EPSS 0.06%
- Veröffentlicht 01.10.2025 17:15:40
- Zuletzt bearbeitet 08.10.2025 20:24:06
In Splunk Enterprise versions below 9.4.4, 9.3.6, and 9.2.8, and Splunk Cloud Platform versions below 9.3.2411.108, 9.3.2408.118 and 9.2.2406.123, a low privilege user that does not hold the "admin" or "power" Splunk roles could perform an extensible...
CVE-2025-20370
- EPSS 0.1%
- Veröffentlicht 01.10.2025 17:15:40
- Zuletzt bearbeitet 08.10.2025 20:24:31
In Splunk Enterprise versions below 10.0.1, 9.4.4, 9.3.6, and 9.2.8, and Splunk Cloud Platform versions below 9.3.2411.108, 9.3.2408.118 and 9.2.2406.123, a user who holds a role that contains the high-privilege capability `change_authentication`, co...
CVE-2025-20371
- EPSS 0.08%
- Veröffentlicht 01.10.2025 17:15:40
- Zuletzt bearbeitet 08.10.2025 20:25:35
In Splunk Enterprise versions below 10.0.1, 9.4.4, 9.3.6 and 9.2.8, and Splunk Cloud Platform versions below 9.3.2411.109, 9.3.2408.119 and 9.2.2406.122, an unauthenticated attacker could trigger a blind server-side request forgery (SSRF) potentially...
CVE-2025-20366
- EPSS 0.04%
- Veröffentlicht 01.10.2025 17:15:39
- Zuletzt bearbeitet 08.10.2025 20:36:04
In Splunk Enterprise versions below 9.4.4, 9.3.6, and 9.2.8, and Splunk Cloud Platform versions below 9.3.2411.111, 9.3.2408.119, and 9.2.2406.122, a low-privileged user that does not hold the admin or power Splunk roles could access sensitive search...
CVE-2025-20367
- EPSS 0.05%
- Veröffentlicht 01.10.2025 17:15:39
- Zuletzt bearbeitet 08.10.2025 20:22:49
In Splunk Enterprise versions below 9.4.4, 9.3.6 and 9.2.8, and Splunk Cloud Platform versions below 9.3.2411.109, 9.3.2408.119 and 9.2.2406.122, a low-privileged user that does not hold the 'admin' or 'power' Splunk roles could craft a malicious pay...
CVE-2025-20368
- EPSS 0.05%
- Veröffentlicht 01.10.2025 17:15:39
- Zuletzt bearbeitet 08.10.2025 20:22:57
In Splunk Enterprise versions below 9.4.4, 9.3.6, and 9.2.8, and Splunk Cloud Platform versions below 9.3.2411.108, 9.3.2408.118 and 9.2.2406.123, a low privileged user that does not hold the admin or power Splunk roles could craft a malicious payloa...