CVE-2017-12572 - Cross-Site Scripting (XSS) vulnerability in Splunk

Publication

2017-08-05

Last modification

2017-08-15

Summary

Persistent Cross Site Scripting (XSS) exists in Splunk Enterprise 6.5.x before 6.5.2, 6.4.x before 6.4.6, and 6.3.x before 6.3.9 and Splunk Light before 6.5.2, with exploitation requiring administrative access, aka SPL-134104.

Classification

CWE-79 - Cross-Site Scripting (XSS)

Risk level (CVSS AV:N/AC:M/Au:S/C:N/I:P/A:N)

Low

3.5

Access Vector

  • Network
  • Adjacent Network
  • Local

Access Complexity

  • Low
  • Medium
  • High

Authentication

  • None
  • Single
  • Multiple

Confident. Impact

  • Complete
  • Partial
  • None

Integrity Impact

  • Complete
  • Partial
  • None

Affected Products

Vendor Product Versions
Splunk Splunk  6.4.4 , 6.4.5 , 6.3.2 , 6.5.0 , 6.3.4 , 6.3.1 , 6.5.1 , 6.3.3 , 6.3.8 , 6.3.6 , 6.3.7 , 6.4.0 , 6.3.0 , 6.4.2 , 6.4.3 , 6.3.5 , 6.4.1