Vulnerabilities > Splunk > Splunk Cloud Platform > 9.0.2209

DATE CVE VULNERABILITY TITLE RISK
2023-08-30 CVE-2023-40592 Cross-site Scripting vulnerability in Splunk and Splunk Cloud Platform
In Splunk Enterprise versions below 9.1.1, 9.0.6, and 8.2.12, an attacker can craft a special web request that can result in reflected cross-site scripting (XSS) on the “/app/search/table” web endpoint.
network
low complexity
splunk CWE-79
6.1
2023-08-30 CVE-2023-40593 Unspecified vulnerability in Splunk and Splunk Cloud Platform
In Splunk Enterprise versions lower than 9.0.6 and 8.2.12, a malicious actor can send a malformed security assertion markup language (SAML) request to the `/saml/acs` REST endpoint which can cause a denial of service through a crash or hang of the Splunk daemon.
network
low complexity
splunk
7.5
2023-08-30 CVE-2023-40594 Unspecified vulnerability in Splunk and Splunk Cloud Platform
In Splunk Enterprise versions lower than 8.2.12, 9.0.6, and 9.1.1, an attacker can use the `printf` SPL function to perform a denial of service (DoS) against the Splunk Enterprise instance.
network
low complexity
splunk
7.5
2023-08-30 CVE-2023-40595 Deserialization of Untrusted Data vulnerability in Splunk and Splunk Cloud Platform
In Splunk Enterprise versions lower than 8.2.12, 9.0.6, and 9.1.1, an attacker can execute a specially crafted query that they can then use to serialize untrusted data.
network
low complexity
splunk CWE-502
8.8
2023-08-30 CVE-2023-40597 Path Traversal vulnerability in Splunk and Splunk Cloud Platform
In Splunk Enterprise versions lower than 8.2.12, 9.0.6, and 9.1.1, an attacker can exploit an absolute path traversal to execute arbitrary code that is located on a separate disk.
local
low complexity
splunk CWE-22
8.8
2023-08-30 CVE-2023-40598 Missing Authentication for Critical Function vulnerability in Splunk
In Splunk Enterprise versions below 8.2.12, 9.0.6, and 9.1.1, an attacker can create an external lookup that calls a legacy internal function.
network
low complexity
splunk CWE-306
8.8
2023-06-01 CVE-2023-32706 XXE vulnerability in Splunk and Splunk Cloud Platform
On Splunk Enterprise versions below 9.0.5, 8.2.11, and 8.1.14, an unauthenticated attacker can send specially-crafted messages to the XML parser within SAML authentication to cause a denial of service in the Splunk daemon.
network
low complexity
splunk CWE-611
6.5
2023-06-01 CVE-2023-32707 Unspecified vulnerability in Splunk and Splunk Cloud Platform
In versions of Splunk Enterprise below 9.0.5, 8.2.11, and 8.1.14, and Splunk Cloud Platform below version 9.0.2303.100, a low-privileged user who holds a role that has the ‘edit_user’ capability assigned to it can escalate their privileges to that of the admin user by providing specially crafted web requests.
network
low complexity
splunk
8.8
2023-06-01 CVE-2023-32708 Interpretation Conflict vulnerability in Splunk and Splunk Cloud Platform
In Splunk Enterprise versions below 9.0.5, 8.2.11, and 8.1.14, and Splunk Cloud Platform versions below 9.0.2303.100, a low-privileged user can trigger an HTTP response splitting vulnerability with the ‘rest’ SPL command that lets them potentially access other REST endpoints in the system arbitrarily.
network
low complexity
splunk CWE-436
8.8
2023-06-01 CVE-2023-32709 Unspecified vulnerability in Splunk and Splunk Cloud Platform
In Splunk Enterprise versions below 9.0.5, 8.2.11.
network
low complexity
splunk
4.3