Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

Splunk Enterprise — Vulnerabilities & Security Advisories 161

All 161 CVE vulnerabilities found in Splunk Enterprise, with AI-generated Chinese analysis, references, and POCs.

This page documents known weaknesses in Splunk Enterprise, a software product developed by Splunk Inc. It aggregates vulnerability data associated with Common Weakness Enumeration classifications and specific software tags relevant to the application’s architecture and deployment models. The content covers publicly disclosed security issues and internal advisory reports spanning from the initial release of the software through the present day. Readers can use this resource to track a vendor's advisories, understand the impact and characteristics of a specific weakness class, or look up a product's vulnerability history. By consolidating information from multiple sources, this aggregation provides a comprehensive view of the security posture of Splunk Enterprise over time. The data includes details on affected versions, remediation steps, and references to external security bulletins. This approach facilitates better risk assessment for security professionals managing Splunk deployments. It allows users to identify patterns in defect discovery and prioritize patching efforts based on the severity and prevalence of the vulnerabilities. The page serves as a neutral repository for factual security information, enabling users to make informed decisions about system updates and configuration changes. It does not interpret the severity levels but presents the available evidence for each reported issue.

Vendor: Splunk Inc.

CVE IDTitleCVSSSeverityPublished
CVE-2023-22942 Cross-Site Request Forgery in the ‘ssg/kvstore_client’ REST Endpoint in Splunk Enterprise CWE-352 5.4 Medium2023-02-14
CVE-2023-22936 Authenticated Blind Server Side Request Forgery via the ‘search_listener’ Search Parameter in Splunk Enterprise CWE-918 6.3 Medium2023-02-14
CVE-2023-22931 ‘createrss’ External Search Command Overwrites Existing RSS Feeds in Splunk Enterprise CWE-285 4.3 Medium2023-02-14
CVE-2023-22941 Improperly Formatted ‘INGEST_EVAL’ Parameter Crashes Splunk Daemon CWE-248 6.5 Medium2023-02-14
CVE-2023-22935 SPL Command Safeguards Bypass via the ‘display.page.search.patterns.sensitivity’ Search Parameter in Splunk Enterprise CWE-20 8.1 High2023-02-14
CVE-2023-22934 SPL Command Safeguards Bypass via the ‘pivot’ SPL Command in Splunk Enterprise CWE-20 7.3 High2023-02-14
CVE-2023-22940 SPL Command Safeguards Bypass via the ‘collect’ SPL Command Aliases in Splunk Enterprise CWE-20 6.3 Medium2023-02-14
CVE-2022-43572 Indexing blockage via malformed data sent through S2S or HEC protocols in Splunk Enterprise CWE-400 7.5 High2022-11-04
CVE-2022-43570 XML External Entity Injection through a custom View in Splunk Enterprise CWE-611 8.8 High2022-11-04
CVE-2022-43569 Persistent Cross-Site Scripting via a Data Model object name in Splunk Enterprise CWE-79 8.0 High2022-11-04
CVE-2022-43568 Reflected Cross-Site Scripting via the radio template in Splunk Enterprise CWE-79 8.8 High2022-11-04
CVE-2022-43567 Remote Code Execution via the Splunk Secure Gateway application Mobile Alerts feature CWE-502 8.8 High2022-11-04
CVE-2022-43566 Risky command safeguards bypass via Search ID query in Analytics Workspace in Splunk Enterprise CWE-20 7.3 High2022-11-04
CVE-2022-43565 Risky command safeguards bypass via ‘tstats command JSON in Splunk Enterprise CWE-20 8.1 High2022-11-04
CVE-2022-43564 Denial of Service in Splunk Enterprise through search macros CWE-400 4.9 Medium2022-11-04
CVE-2022-43563 Risky command safeguards bypass via rex search command field names in Splunk Enterprise CWE-20 8.1 High2022-11-04
CVE-2022-43562 Host Header Injection in Splunk Enterprise CWE-20 3.0 Low2022-11-04
CVE-2022-43571 Remote Code Execution through dashboard PDF generation component in Splunk Enterprise CWE-94 8.8 High2022-11-03
CVE-2022-43561 Persistent Cross-Site Scripting in “Save Table” Dialog in Splunk Enterprise CWE-79 6.4 Medium2022-11-03
CVE-2022-37437 Ingest Actions UI in Splunk Enterprise 9.0.0 disabled TLS certificate validation CWE-295 7.4 High2022-08-16
CVE-2022-37439 Malformed ZIP file crashes Universal Forwarders and Splunk Enterprise through file monitoring input CWE-409 5.5 Medium2022-08-16
CVE-2022-37438 Information disclosure via the dashboard drilldown in Splunk Enterprise CWE-200 2.6 Low2022-08-16
CVE-2022-32158 Splunk Enterprise deployment servers allow client publishing of forwarder bundles CWE-284 9.0 Critical2022-06-15
CVE-2022-32157 Splunk Enterprise deployment servers allow unauthenticated forwarder bundle downloads CWE-306 7.5 High2022-06-15
CVE-2022-32154 Risky commands warnings in Splunk Enterprise Dashboards CWE-20 6.8 Medium2022-06-15
CVE-2022-32153 Splunk Enterprise lacked TLS host name validation CWE-297 8.1 High2022-06-15
CVE-2022-32152 Splunk Enterprise lacked TLS cert validation for Splunk-to-Splunk communication by default CWE-295 8.1 High2022-06-15
CVE-2022-32151 Splunk Enterprise disabled TLS validation using the CA certificate stores in Python 3 libraries by default CWE-295 7.4 High2022-06-15
CVE-2022-32156 Splunk Enterprise and Universal Forwarder CLI connections lacked TLS cert validation CWE-295 8.1 High2022-06-14
CVE-2022-27183 Reflected XSS in a query parameter of the Monitoring Console CWE-79 8.8 High2022-05-06

All 161 known CVE vulnerabilities affecting Splunk Enterprise with full Chinese analysis, references, and POCs where available.