CVE-2022-43564: Denial of Service in Splunk Enterprise through search macros
In Splunk Enterprise versions below 8.1.12, 8.2.9, and 9.0.2, a remote user who can create search macros and schedule search reports can cause a denial of service through the use of specially crafted search macros.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Splunk Enterpriseto a version that resolves this vulnerability.Fixed in 8.1.12 - Upgrade
Upgrade
Splunk Enterpriseto a version that resolves this vulnerability.Fixed in 8.2.9 - Upgrade
Upgrade
Splunk Enterpriseto a version that resolves this vulnerability.Fixed in 9.0.2
Event History
Frequently Asked Questions
What is the vulnerability ID for this Splunk Enterprise vulnerability?
The vulnerability ID for this Splunk Enterprise vulnerability is CVE-2022-43564.
What is the severity of CVE-2022-43564?
The severity of CVE-2022-43564 is medium (CVSS 6.5).
What is the affected software for CVE-2022-43564?
The affected software for CVE-2022-43564 is Splunk Enterprise versions below 8.1.12, 8.2.9, and 9.0.2.
What can a remote user do with CVE-2022-43564?
A remote user who can create search macros and schedule search reports can cause a denial of service through the use of specially crafted search macros.
How can I fix CVE-2022-43564?
To fix CVE-2022-43564, it is recommended to upgrade Splunk Enterprise to version 8.1.12, 8.2.9, or 9.0.2 or later.