Vulnerabilities > CVE-2022-43567 - Deserialization of Untrusted Data vulnerability in Splunk and Splunk Cloud Platform

047910
CVSS 8.8 - HIGH
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
LOW
Confidentiality impact
HIGH
Integrity impact
HIGH
Availability impact
HIGH
network
low complexity
splunk
CWE-502

Summary

In Splunk Enterprise versions below 8.2.9, 8.1.12, and 9.0.2, an authenticated user can run arbitrary operating system commands remotely through the use of specially crafted requests to the mobile alerts feature in the Splunk Secure Gateway app.

Common Weakness Enumeration (CWE)