CRITICAL🇵🇱 Wersja polska

CVE-2017-17067

CVSS 9.8v3.0pub. 2017-11-30upd. 2026-05-13

Splunk Web in Splunk Enterprise 7.0.x before 7.0.0.1, 6.6.x before 6.6.3.2, 6.5.x before 6.5.6, 6.4.x before 6.4.9, and 6.3.x before 6.3.12, when the SAML authType is enabled, mishandles SAML, which allows remote attackers to bypass intended access restrictions or conduct impersonation attacks.

CVSS Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
  • Splunk

    APP
    Splunk
    6.3.0 – 6.3.12 (excl.)6.4.0 – 6.4.9 (excl.)6.5.0 – 6.5.6 (excl.)6.6.0 – 6.6.3.2 (excl.)7.0.0 – 7.0.0.1 (excl.)
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
CWE
References

Related vulnerabilities

CVE-2026-20253CRITICAL9.8⚠ KEVPL ✓same product

Splunk Enterprise — tworzenie/skracanie plików bez uwierzytelnienia przez sidecar PostgreSQL

CVE-2026-76312CRITICAL9.4same product

In Splunk Enterprise versions below 10.4.1, 10.2.6, 10.0.9, and 9.4.14, an unauthenticated user who can read t...

CVE-2026-76311CRITICAL9.4same product

In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, an unauthenticated user who has an emb...

CVE-2026-76310CRITICAL9.4same product

In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, an unauthenticated user who has an emb...

CVE-2022-32158CRITICAL9.0PL ✓same product

Splunk Enterprise: RCE przez deployment server na wszystkich Universal Forwarder