CVE-2016-4858: XSS
Cross-site scripting vulnerability in Splunk Enterprise 6.4.x prior to 6.4.2, Splunk Enterprise 6.3.x prior to 6.3.6, Splunk Enterprise 6.2.x prior to 6.2.10, Splunk Enterprise 6.1.x prior to 6.1.11, Splunk Enterprise 6.0.x prior to 6.0.12, Splunk Enterprise 5.0.x prior to 5.0.16 and Splunk Light prior to 6.4.2 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2016-4858?
CVE-2016-4858 is classified as a medium severity vulnerability due to the potential for cross-site scripting attacks.
How do I fix CVE-2016-4858?
To fix CVE-2016-4858, upgrade Splunk Enterprise to versions 6.4.2 or later, 6.3.6 or later, 6.2.10 or later, 6.1.11 or later, 6.0.12 or later, or 5.0.16 or later.
What versions of Splunk are affected by CVE-2016-4858?
CVE-2016-4858 affects Splunk Enterprise versions 5.0.x through 6.4.1 and Splunk Light prior to the patched versions.
Can CVE-2016-4858 be exploited remotely?
Yes, CVE-2016-4858 can be exploited remotely if a user is tricked into clicking on a malicious link.
What types of attacks can CVE-2016-4858 lead to?
CVE-2016-4858 can lead to cross-site scripting (XSS) attacks, potentially allowing unauthorized actions to be performed on behalf of a user.