CVE-2018-7432: Input Validation
Published Oct 23, 2018
·Updated
Splunk Enterprise 6.2.x before 6.2.14, 6.3.x before 6.3.10, 6.4.x before 6.4.7, and 6.5.x before 6.5.3; and Splunk Light before 6.6.0 allow remote attackers to cause a denial of service via a crafted HTTP request.
Affected Software
5 affected components
Splunk splunk<6.6.0
Splunk splunk>=6.2.0<6.2.14
Splunk splunk>=6.3.0<6.3.10
Splunk splunk>=6.4.0<6.4.7
Splunk splunk>=6.5.0<6.5.3
Event History
Oct 23, 2018
CVE Published
via MITRE·09:00 PM
Data Sourced
via MITRE·09:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2018-7432?
CVE-2018-7432 has a severity rating that allows for potential denial of service attacks.
2
How do I fix CVE-2018-7432?
To fix CVE-2018-7432, update Splunk Enterprise or Splunk Light to the latest versions as recommended in the advisory.
3
Which versions of Splunk are affected by CVE-2018-7432?
CVE-2018-7432 affects Splunk Enterprise versions 6.2.x through 6.5.x and Splunk Light before version 6.6.0.
4
Can CVE-2018-7432 be exploited remotely?
Yes, CVE-2018-7432 can be exploited remotely by sending a crafted HTTP request.
5
What impact does CVE-2018-7432 have on systems?
The impact of CVE-2018-7432 is a denial of service, which can make the affected Splunk services unavailable.