CERT-In Advisory
CIAD-2024-0037
Multiple Vulnerabilities in Splunk
Original Issue Date: July 23, 2024
Severity Rating: High
Component Affected
- Splunk Enterprise versions below 9.2.2, 9.1.5, and 9.0.10
- Splunk Cloud Platform versions below 9.1.2312.200 and 9.1.2308.207
Overview
Multiple vulnerabilities have been reported in Splunk platforms which could allow an attacker to execute arbitrary code, bypass security restrictions, disclose sensitive information and perform denial of service (DoS) conditions on the targeted system.
Description
Multiple vulnerabilities have been reported in Splunk platforms; details of which are provided below:

Solution
Apply appropriate fixes/work arounds as mentioned in Splunk Security Advisory:
https://advisory.splunk.com/advisories
Vendor Information
Splunk
https://advisory.splunk.com/advisories
References
Splunk
https://advisory.splunk.com/advisories
CVE Name
CVE-2024-36997
CVE-2024-36996
CVE-2024-36995
CVE-2024-36994
CVE-2024-36993
CVE-2024-36992
CVE-2024-36991
CVE-2024-36990
CVE-2024-36989
CVE-2024-36987
CVE-2024-36986
CVE-2024-36985
CVE-2024-36984
CVE-2024-36983
CVE-2024-36982
Disclaimer
The information provided herein is on "as is" basis, without warranty of any kind.
Contact Information
Email: info@cert-in.org.in Phone: +91-11-22902657
Postal address
Indian Computer Emergency Response Team (CERT-In) Ministry of Electronics and Information Technology Government of India Electronics Niketan 6, CGO Complex, Lodhi Road, New Delhi - 110 003 India
|