CVE-2022-43567
8.8
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Exploitability: 2.8 / Impact: 5.9
Source: NVD
Description
In Splunk Enterprise versions below 8.2.9, 8.1.12, and 9.0.2, an authenticated user can run arbitrary operating system commands remotely through the use of specially crafted requests to the mobile alerts feature in the Splunk Secure Gateway app.
Affected (4)
Products: Splunk: Splunk, Splunk Cloud Platform
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| From 8.1.0 to 8.1.12 | |
| Before 9.0.2205 |
References (4)
Source: prodsec@splunk.com
ExploitVendor Advisory
Source: prodsec@splunk.com
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
ExploitVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Timeline
No history available yet.