Splunk Web in Splunk Enterprise 5.0.x before 5.0.17, 6.0.x before 6.0.13, 6.1.x before 6.1.12, 6.2.x before 6.2.12, 6.3.x before 6.3.8, and 6.4.x before 6.4.4 allows remote attackers to conduct HTTP request injection attacks and obtain sensitive REST API authentication-token information via unspecified vectors, aka SPL-128840.
References
Link | Resource |
---|---|
http://www.securityfocus.com/bid/95412 | |
https://www.splunk.com/view/SP-CAAAPSR | Mitigation Vendor Advisory |
http://www.securityfocus.com/bid/95412 | |
https://www.splunk.com/view/SP-CAAAPSR | Mitigation Vendor Advisory |
Configurations
Configuration 1 (hide)
|
Configuration 2 (hide)
|
Configuration 3 (hide)
|
Configuration 4 (hide)
|
Configuration 5 (hide)
|
Configuration 6 (hide)
|
History
21 Nov 2024, 02:43
Type | Values Removed | Values Added |
---|---|---|
References | () http://www.securityfocus.com/bid/95412 - | |
References | () https://www.splunk.com/view/SP-CAAAPSR - Mitigation, Vendor Advisory |
Information
Published : 2017-01-10 11:59
Updated : 2024-11-21 02:43
NVD link : CVE-2016-10126
Mitre link : CVE-2016-10126
CVE.ORG link : CVE-2016-10126
JSON object : View
Products Affected
splunk
- splunk
CWE
CWE-264
Permissions, Privileges, and Access Controls