Lucene search

K
cve[email protected]CVE-2016-10126
HistoryJan 10, 2017 - 11:59 a.m.

CVE-2016-10126

2017-01-1011:59:00
CWE-264
web.nvd.nist.gov
15
cve-2016-10126
splunk web
splunk enterprise
http request injection
rest api
authentication-token
spl-128840
nvd

10 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:L/Au:N/C:C/I:C/A:C

9.8 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

9.3 High

AI Score

Confidence

High

0.003 Low

EPSS

Percentile

70.2%

Splunk Web in Splunk Enterprise 5.0.x before 5.0.17, 6.0.x before 6.0.13, 6.1.x before 6.1.12, 6.2.x before 6.2.12, 6.3.x before 6.3.8, and 6.4.x before 6.4.4 allows remote attackers to conduct HTTP request injection attacks and obtain sensitive REST API authentication-token information via unspecified vectors, aka SPL-128840.

Affected configurations

NVD
Node
splunksplunkMatch5.0.0enterprise
OR
splunksplunkMatch5.0.1enterprise
OR
splunksplunkMatch5.0.2enterprise
OR
splunksplunkMatch5.0.3enterprise
OR
splunksplunkMatch5.0.4enterprise
OR
splunksplunkMatch5.0.5enterprise
OR
splunksplunkMatch5.0.6enterprise
OR
splunksplunkMatch5.0.7enterprise
OR
splunksplunkMatch5.0.8enterprise
OR
splunksplunkMatch5.0.9enterprise
OR
splunksplunkMatch5.0.10enterprise
OR
splunksplunkMatch5.0.11enterprise
OR
splunksplunkMatch5.0.12enterprise
OR
splunksplunkMatch5.0.13enterprise
OR
splunksplunkMatch5.0.14enterprise
OR
splunksplunkMatch5.0.15enterprise
OR
splunksplunkMatch5.0.16enterprise
Node
splunksplunkMatch6.0.0enterprise
OR
splunksplunkMatch6.0.1enterprise
OR
splunksplunkMatch6.0.2enterprise
OR
splunksplunkMatch6.0.3enterprise
OR
splunksplunkMatch6.0.4enterprise
OR
splunksplunkMatch6.0.5enterprise
OR
splunksplunkMatch6.0.6enterprise
OR
splunksplunkMatch6.0.7enterprise
OR
splunksplunkMatch6.0.8enterprise
OR
splunksplunkMatch6.0.9enterprise
OR
splunksplunkMatch6.0.10enterprise
OR
splunksplunkMatch6.0.11enterprise
OR
splunksplunkMatch6.0.12enterprise
Node
splunksplunkMatch6.1.0enterprise
OR
splunksplunkMatch6.1.1enterprise
OR
splunksplunkMatch6.1.2enterprise
OR
splunksplunkMatch6.1.3enterprise
OR
splunksplunkMatch6.1.4enterprise
OR
splunksplunkMatch6.1.5enterprise
OR
splunksplunkMatch6.1.6enterprise
OR
splunksplunkMatch6.1.7enterprise
OR
splunksplunkMatch6.1.8enterprise
OR
splunksplunkMatch6.1.9enterprise
OR
splunksplunkMatch6.1.10enterprise
OR
splunksplunkMatch6.1.11enterprise
Node
splunksplunkMatch6.2.0enterprise
OR
splunksplunkMatch6.2.1enterprise
OR
splunksplunkMatch6.2.2enterprise
OR
splunksplunkMatch6.2.3enterprise
OR
splunksplunkMatch6.2.4enterprise
OR
splunksplunkMatch6.2.5enterprise
OR
splunksplunkMatch6.2.6enterprise
OR
splunksplunkMatch6.2.7enterprise
OR
splunksplunkMatch6.2.8enterprise
OR
splunksplunkMatch6.2.9enterprise
OR
splunksplunkMatch6.2.10enterprise
OR
splunksplunkMatch6.2.11enterprise
Node
splunksplunkMatch6.3.0enterprise
OR
splunksplunkMatch6.3.1enterprise
OR
splunksplunkMatch6.3.2enterprise
OR
splunksplunkMatch6.3.3enterprise
OR
splunksplunkMatch6.3.4enterprise
OR
splunksplunkMatch6.3.5enterprise
OR
splunksplunkMatch6.3.6enterprise
OR
splunksplunkMatch6.3.7enterprise
Node
splunksplunkMatch6.4.0enterprise
OR
splunksplunkMatch6.4.1enterprise
OR
splunksplunkMatch6.4.2enterprise
OR
splunksplunkMatch6.4.3enterprise

10 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:L/Au:N/C:C/I:C/A:C

9.8 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

9.3 High

AI Score

Confidence

High

0.003 Low

EPSS

Percentile

70.2%

Related for CVE-2016-10126