First published: Fri Nov 04 2022(Updated: )
In Splunk Enterprise versions below 8.1.12, 8.2.9, and 9.0.2, a remote user who can create search macros and schedule search reports can cause a denial of service through the use of specially crafted search macros.
Credit: prodsec@splunk.com prodsec@splunk.com
Affected Software | Affected Version | How to fix |
---|---|---|
Splunk Splunk | >=8.1.0<8.1.12 | |
Splunk Splunk | >=8.2.0<8.2.9 | |
Splunk Splunk Cloud Platform | <9.0.2205 | |
>=8.1.0<8.1.12 | ||
>=8.2.0<8.2.9 | ||
<9.0.2205 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this Splunk Enterprise vulnerability is CVE-2022-43564.
The severity of CVE-2022-43564 is medium (CVSS 6.5).
The affected software for CVE-2022-43564 is Splunk Enterprise versions below 8.1.12, 8.2.9, and 9.0.2.
A remote user who can create search macros and schedule search reports can cause a denial of service through the use of specially crafted search macros.
To fix CVE-2022-43564, it is recommended to upgrade Splunk Enterprise to version 8.1.12, 8.2.9, or 9.0.2 or later.