CVE漏洞中文网

0DayBank一个专门收集整理全球互联网漏洞的公开发布网站
  1. 首页
  2. CVE
  3. 正文

CVE-2016-2107 Splunk Enterprise and Light Multiple Vulnerabilities (SP-CAAAPQM)

2016年10月6日 2220点热度 0人点赞 0条评论

漏洞类别:CGI

漏洞等级:

漏洞信息

Splunk is a log monitoring and reporting tool with search capabilities. Splunk Enterprise and Splunk Light are exposed to following vulnerabilities:

Multiple vulnerabilities in OpenSSL before 1.0.1t and 1.0.2h (SPL-119440)
Multiple vulnerabilities in libarchive before 3.2.1 (SPL-123095)
Multiple vulnerabilities in libxml2 prior to 2.9.4 (SPL-121159)
Open redirect in Splunk Web (SPL-119464)
Cross-Site Scripting Vulnerability in Splunk Web (SPL-118666)

Affected Versions Prior to:
Splunk Enterprise 6.4.2, 6.3.6, 6.2.11, 6.1.11, 6.0.12 and 5.0.16
Splunk Light 6.4.2

漏洞危害

Successfully exploiting these vulnerabilities might allow an attacker to perform cross-site scripting attacks, execute arbitrary code or redirect user to an attacker controlled website.

解决方案

Vendor has released updated versions to fix these vulnerabilities. Please refer Splunk SP-CAAAPQM for more details.

Patch:
Following are links for downloading patches to fix the vulnerabilities:

SP-CAAAPQM

0day

标签: 暂无
最后更新:2016年10月22日

小助手

这个人很懒,什么都没留下

点赞
< 上一篇
下一篇 >

文章评论

您需要 登录 之后才可以评论

COPYRIGHT © 2024 www.pdr.cn CVE漏洞中文网. ALL RIGHTS RESERVED.

鲁ICP备2022031030号

联系邮箱:wpbgssyubnmsxxxkkk@proton.me