Splunk Multiple Vulnerabilities
Last Update Date:
20 Nov 2012 17:36
Release Date:
20 Nov 2012
4711
Views
RISK: Medium Risk
TYPE: Servers - Other Servers
Some vulnerabilities have been identified in Splunk, which can be exploited by malicious people to conduct cross-site scripting attacks and cause a DoS (Denial of Service).
- Certain unspecified input passed to the Splunk Web component is not properly sanitised before being returned to the user. This can be exploited to execute arbitrary HTML and script code in a user's browser session in context of an affected site.
Successful exploitation of this vulnerability requires that the victim uses a non-RFC compliant browser. - Certain unspecified input passed to the Splunk Web component is not properly sanitised before being returned to the user. This can be exploited to execute arbitrary HTML and script code in a user's browser session in context of an affected site.
- An unspecified error within Splunkd when handling splunktcp inputs can be exploited to render the service unusable.
Successful exploitation of this vulnerability requires that splunktcp inputs are enabled (disabled by default).
Impact
- Cross-Site Scripting
- Denial of Service
System / Technologies affected
- Splunk 4.x
Solutions
Before installation of the software, please visit the software manufacturer web-site for more details.
- Update to version 4.3.5.
Vulnerability Identifier
- No CVE information is available
Source
Related Link
Share with