Splunk

Splunk

282 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.25%
  • Veröffentlicht 19.08.2026 21:34:34
  • Zuletzt bearbeitet 27.08.2026 17:20:14

In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, an unauthenticated user could trick an authenticated user into opening a crafted link to Analytics Workspace. When the authenticated user opens the link, Splunk Enterprise runs a...

  • EPSS 0.25%
  • Veröffentlicht 19.08.2026 21:34:34
  • Zuletzt bearbeitet 26.08.2026 16:16:40

In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, a user who holds the "power" Splunk role could store a Dashboard Studio workflow action with a crafted Uniform Resource Locator (URL). When another authenticated user selects the...

  • EPSS 0.23%
  • Veröffentlicht 19.08.2026 21:34:33
  • Zuletzt bearbeitet 27.08.2026 17:20:14

In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, a user who does not hold the "admin" or "power" Splunk roles could inject Search Processing Language (SPL) into saved-search dispatch requests. This could allow for unauthorized ...

  • EPSS 0.2%
  • Veröffentlicht 19.08.2026 21:34:32
  • Zuletzt bearbeitet 26.08.2026 16:16:39

In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, an unauthenticated user could trick a user who holds the "admin" Splunk role into opening a crafted link to Monitoring Console. When that user opens the link, Splunk Enterprise r...

  • EPSS 0.25%
  • Veröffentlicht 19.08.2026 21:34:32
  • Zuletzt bearbeitet 27.08.2026 17:20:13

In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, an unauthenticated user could trick an authenticated user into opening a crafted link to Monitoring Console. When the authenticated user opens the link, Splunk Enterprise runs at...

  • EPSS 0.21%
  • Veröffentlicht 19.08.2026 21:34:31
  • Zuletzt bearbeitet 26.08.2026 16:16:39

In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, and Splunk Secure Gateway versions below 3.10.9, 3.9.23, and 3.8.70, an unauthenticated user could trick a user who holds the "admin" or "sc_admin" Splunk roles into opening a cr...

  • EPSS 0.2%
  • Veröffentlicht 19.08.2026 21:34:31
  • Zuletzt bearbeitet 27.08.2026 17:20:13

In Splunk Enterprise versions below 10.4.1, 10.2.6, 10.0.9, and 9.4.14, a user who holds the "power" Splunk role could store attacker-controlled Search Processing Language (SPL) in a dashboard. When another authenticated user exports the dashboard as...

  • EPSS 0.24%
  • Veröffentlicht 19.08.2026 21:34:30
  • Zuletzt bearbeitet 26.08.2026 16:16:39

In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, a user who does not hold the "admin" or "power" Splunk roles could store a dashboard view that runs JavaScript in the browser of another user who opens it and hovers over a spark...

  • EPSS 0.3%
  • Veröffentlicht 19.08.2026 21:34:29
  • Zuletzt bearbeitet 26.08.2026 16:16:39

In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, a user who holds the "power" Splunk role could create a malicious Splunk Web tour and cause arbitrary JavaScript to run in the browser of another user when that user opens a craf...

  • EPSS 0.25%
  • Veröffentlicht 19.08.2026 21:34:29
  • Zuletzt bearbeitet 26.08.2026 16:16:39

In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, a user who holds the "power" Splunk role could store a malicious ui-tour knowledge object that matches an auto-tour page name and share the object at the app level. The object ca...