CVE-2018-11409
82Vexday Risk Score
Patch now. It exploitation observed by VulnCheck and has a working public exploit.
ssvc Actepss 98%
from disclosure to weapon0 days
Published on NVDJun 8
1st PoCJun 8
metasploitJun 8
VulnCheck+1997d
exploitation probability
98%top 1% of all CVEs
observed exploitation
yesVulnCheck
2 public exploit(s)
Splunk through 7.0.1 allows information disclosure by appending __raw/services/server/info/server-info?output_mode=json to a query, as demonstrated by discovering a license key.
Affected products
n/a · n/apublic PoCs found — 2
exploitdbwww.exploit-db.com/exploits/44865unverifiedcve_referencewww.exploit-db.com/exploits/44865/unverified⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.