Vulnerabilities > Splunk > Critical

DATE CVE VULNERABILITY TITLE RISK
2017-11-30 CVE-2017-17067 Incorrect Authorization vulnerability in Splunk
Splunk Web in Splunk Enterprise 7.0.x before 7.0.0.1, 6.6.x before 6.6.3.2, 6.5.x before 6.5.6, 6.4.x before 6.4.9, and 6.3.x before 6.3.12, when the SAML authType is enabled, mishandles SAML, which allows remote attackers to bypass intended access restrictions or conduct impersonation attacks.
network
low complexity
splunk CWE-863
critical
9.8
2017-01-10 CVE-2016-10126 Permissions, Privileges, and Access Controls vulnerability in Splunk
Splunk Web in Splunk Enterprise 5.0.x before 5.0.17, 6.0.x before 6.0.13, 6.1.x before 6.1.12, 6.2.x before 6.2.12, 6.3.x before 6.3.8, and 6.4.x before 6.4.4 allows remote attackers to conduct HTTP request injection attacks and obtain sensitive REST API authentication-token information via unspecified vectors, aka SPL-128840.
network
low complexity
splunk CWE-264
critical
9.8