Remote code execution (RCE) in Splunk Enterprise through Insecure XML Parsing
58Vexday Risk Score
Corrige pronto. Ella tiene exploit funcional público.
ssvc Attendcvss 8epss 89%
de la publicación al arma12 días
Publicada en NVD16 nov
metasploit+12d
probabilidad de explotación
89%top 1% de las CVE
explotación observada
noninguna fuente lo reporta
In Splunk Enterprise versions below 9.0.7 and 9.1.2, Splunk Enterprise does not safely sanitize extensible stylesheet language transformations (XSLT) that users supply. This means that an attacker can upload malicious XSLT which can result in remote code execution on the Splunk Enterprise instance.
CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:C/C:H/I:H/A:H