8.8
CVSSv3

CVE-2022-43565

Published: 04/11/2022 Updated: 07/11/2023
CVSS v3 Base Score: 8.8 | Impact Score: 5.9 | Exploitability Score: 2.8
VMScore: 0

Vulnerability Summary

In Splunk Enterprise versions below 8.2.9 and 8.1.12, the way that the ‘tstats command handles Javascript Object Notation (JSON) lets an attacker bypass SPL safeguards for risky commands docs.splunk.com/Documentation/SplunkCloud/latest/Security/SPLsafeguards . The vulnerability requires the malicious user to phish the victim by tricking them into initiating a request within their browser.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

splunk splunk

splunk splunk cloud platform