CVE-2016-4856: XSS
Published May 12, 2017
·Updated
Cross-site scripting vulnerability in Splunk Enterprise 6.3.x prior to 6.3.5 and Splunk Light 6.3.x prior to 6.3.5 allows attacker with administrator rights to inject arbitrary web script or HTML via unspecified vectors.
Affected Software
10 affected components
Splunk splunk=6.3.0
Splunk splunk=6.3.0
Splunk splunk=6.3.1
Splunk splunk=6.3.1
Splunk splunk=6.3.2
Splunk splunk=6.3.2
Splunk splunk=6.3.3
Splunk splunk=6.3.3
Splunk splunk=6.3.4
Splunk splunk=6.3.4
Event History
May 12, 2017
CVE Published
via MITRE·06:00 PM
Data Sourced
via MITRE·06:00 PM
DescriptionWeakness
Frequently Asked Questions
1
What is the severity of CVE-2016-4856?
CVE-2016-4856 is considered a high severity vulnerability due to the potential for an attacker with administrator rights to execute arbitrary web scripts or HTML.
2
How do I fix CVE-2016-4856?
To fix CVE-2016-4856, upgrade Splunk Enterprise and Splunk Light to version 6.3.5 or later.
3
What versions are affected by CVE-2016-4856?
CVE-2016-4856 affects Splunk Enterprise versions 6.3.0 to 6.3.4 and Splunk Light versions 6.3.0 to 6.3.4.
4
Who can exploit CVE-2016-4856?
CVE-2016-4856 can be exploited by an attacker who has administrator rights.
5
What type of vulnerability is CVE-2016-4856?
CVE-2016-4856 is a cross-site scripting (XSS) vulnerability.