CVE-2016-10126: Critical severity splunk vulnerability
Splunk Web in Splunk Enterprise 5.0.x before 5.0.17, 6.0.x before 6.0.13, 6.1.x before 6.1.12, 6.2.x before 6.2.12, 6.3.x before 6.3.8, and 6.4.x before 6.4.4 allows remote attackers to conduct HTTP request injection attacks and obtain sensitive REST API authentication-token information via unspecified vectors, aka SPL-128840.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2016-10126?
CVE-2016-10126 has a moderate severity level, allowing attackers to conduct HTTP request injection attacks.
How do I fix CVE-2016-10126?
To fix CVE-2016-10126, you should upgrade Splunk Enterprise to a version that is 5.0.17 or higher, or 6.0.13 or higher.
What versions of Splunk Enterprise are affected by CVE-2016-10126?
CVE-2016-10126 affects versions of Splunk Enterprise from 5.0.0 up to, but not including, 5.0.17, and similarly for versions 6.0.0 to 6.0.12, as well as several other 6.x versions.
Can CVE-2016-10126 allow access to sensitive information?
Yes, CVE-2016-10126 enables remote attackers to obtain sensitive REST API authentication-token information.
Is CVE-2016-10126 a remote code execution vulnerability?
No, CVE-2016-10126 is an HTTP request injection vulnerability, not a remote code execution vulnerability.