Splunk Web in Splunk Enterprise 5.0.x before 5.0.17, 6.0.x before 6.0.13, 6.1.x before 6.1.12, 6.2.x before 6.2.12, 6.3.x before 6.3.8, and 6.4.x before 6.4.4 allows remote attackers to conduct HTTP request injection attacks and obtain sensitive REST API authentication-token information via unspecified vectors, aka SPL-128840.
References
Link | Resource |
---|---|
https://www.splunk.com/view/SP-CAAAPSR | Mitigation Vendor Advisory |
http://www.securityfocus.com/bid/95412 |
Configurations
Configuration 1 (hide)
|
Configuration 2 (hide)
|
Configuration 3 (hide)
|
Configuration 4 (hide)
|
Configuration 5 (hide)
|
Configuration 6 (hide)
|
Information
Published : 2017-01-10 03:59
Updated : 2017-01-17 18:59
NVD link : CVE-2016-10126
Mitre link : CVE-2016-10126
JSON object : View
CWE
CWE-264
Permissions, Privileges, and Access Controls
Products Affected
splunk
- splunk