The XML parser in Splunk 4.0.0 through 4.1.4 allows remote authenticated users to obtain sensitive information and gain privileges via an XML External Entity (XXE) attack to unknown vectors.
References
Link | Resource |
---|---|
http://www.splunk.com/view/SP-CAAAFQ6 | Patch Vendor Advisory |
Configurations
Configuration 1 (hide)
|
Information
Published : 2010-09-14 10:00
Updated : 2010-09-14 10:00
NVD link : CVE-2010-3322
Mitre link : CVE-2010-3322
JSON object : View
CWE
CWE-264
Permissions, Privileges, and Access Controls
Products Affected
splunk
- splunk