CVE Vulnerabilities

CVE-2016-10126

Published: Jan 10, 2017 | Modified: Jan 18, 2017
CVSS 3.x
9.8
CRITICAL
Source:
NVD
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS 2.x
10 HIGH
AV:N/AC:L/Au:N/C:C/I:C/A:C
RedHat/V2
RedHat/V3
Ubuntu

Splunk Web in Splunk Enterprise 5.0.x before 5.0.17, 6.0.x before 6.0.13, 6.1.x before 6.1.12, 6.2.x before 6.2.12, 6.3.x before 6.3.8, and 6.4.x before 6.4.4 allows remote attackers to conduct HTTP request injection attacks and obtain sensitive REST API authentication-token information via unspecified vectors, aka SPL-128840.

Affected Software

Name Vendor Start Version End Version
Splunk Splunk 5.0.0 (including) 5.0.0 (including)
Splunk Splunk 5.0.1 (including) 5.0.1 (including)
Splunk Splunk 5.0.2 (including) 5.0.2 (including)
Splunk Splunk 5.0.3 (including) 5.0.3 (including)
Splunk Splunk 5.0.4 (including) 5.0.4 (including)
Splunk Splunk 5.0.5 (including) 5.0.5 (including)
Splunk Splunk 5.0.6 (including) 5.0.6 (including)
Splunk Splunk 5.0.7 (including) 5.0.7 (including)
Splunk Splunk 5.0.8 (including) 5.0.8 (including)
Splunk Splunk 5.0.9 (including) 5.0.9 (including)
Splunk Splunk 5.0.10 (including) 5.0.10 (including)
Splunk Splunk 5.0.11 (including) 5.0.11 (including)
Splunk Splunk 5.0.12 (including) 5.0.12 (including)
Splunk Splunk 5.0.13 (including) 5.0.13 (including)
Splunk Splunk 5.0.14 (including) 5.0.14 (including)
Splunk Splunk 5.0.15 (including) 5.0.15 (including)
Splunk Splunk 5.0.16 (including) 5.0.16 (including)

References