CVE-2022-32155

In universal forwarder versions before 9.0, management services are available remotely by default. When not required, it introduces a potential exposure, but it is not a vulnerability. If exposed, we recommend each customer assess the potential severity specific to your environment. In 9.0, the universal forwarder now binds the management port to localhost preventing remote logins by default. If management services are not required in versions before 9.0, set disableDefaultPort = true in server.conf OR allowRemoteLogin = never in server.conf OR mgmtHostPort = localhost in web.conf. See Configure universal forwarder management security (https://docs.splunk.com/Documentation/Splunk/9.0.0/Security/EnableTLSCertHostnameValidation#Configure_universal_forwarder_management_security) for more information on disabling the remote management services.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:splunk:splunk:*:*:*:*:enterprise:*:*:*
cpe:2.3:a:splunk:splunk_cloud_platform:*:*:*:*:*:*:*:*

History

21 Nov 2024, 07:05

Type Values Removed Values Added
References () https://docs.splunk.com/Documentation/Splunk/9.0.0/Security/EnableTLSCertHostnameValidation#Configure_universal_forwarder_management_security - Mitigation, Vendor Advisory () https://docs.splunk.com/Documentation/Splunk/9.0.0/Security/EnableTLSCertHostnameValidation#Configure_universal_forwarder_management_security - Mitigation, Vendor Advisory
References () https://docs.splunk.com/Documentation/Splunk/9.0.0/Security/Updates - Release Notes, Vendor Advisory () https://docs.splunk.com/Documentation/Splunk/9.0.0/Security/Updates - Release Notes, Vendor Advisory
References () https://www.splunk.com/en_us/product-security/announcements/svd-2022-0605.html - Vendor Advisory () https://www.splunk.com/en_us/product-security/announcements/svd-2022-0605.html - Vendor Advisory

Information

Published : 2022-06-15 17:15

Updated : 2024-11-21 07:05


NVD link : CVE-2022-32155

Mitre link : CVE-2022-32155

CVE.ORG link : CVE-2022-32155


JSON object : View

Products Affected

splunk

  • splunk_cloud_platform
  • splunk
CWE
CWE-732

Incorrect Permission Assignment for Critical Resource