PT-2022-3325 · Splunk · Splunk Enterprise

Nadim Taha

·

Published

2022-06-15

·

Updated

2022-07-12

·

CVE-2022-32158

CVSS v3.1

10

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Splunk Enterprise versions prior to 8.1.10.1 Splunk Enterprise versions prior to 8.2.6.1 Splunk Enterprise versions prior to 9.0
Description The issue is related to inadequate access control in Splunk Enterprise deployment servers, allowing an attacker who has compromised a Universal Forwarder endpoint to execute arbitrary code on other Universal Forwarder endpoints subscribed to the deployment server. This can be done by deploying forwarder bundles to other deployment clients through the deployment server.
Recommendations For versions prior to 8.1.10.1, update to version 8.1.10.1 or later. For versions prior to 8.2.6.1, update to version 8.2.6.1 or later. For versions prior to 9.0, update to version 9.0 or later.

Fix

Improper Access Control

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2022-04073
CVE-2022-32158

Affected Products

Splunk Enterprise