VDB

GCVE-110-NCSC-2025-212

GCVE-110-NCSC-2025-212
Advisory PublishedCVSS 4.3/10
Vulnetix · Advisory published July 8, 2025
Splunk heeft kwetsbaarheden verholpen in Splunk Enterprise en Splunk Cloud Platform.

Weaknesses (CWE)

CWE-863Incorrect AuthorizationCWE-78Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')CWE-35Path Traversal: '.../...//'CWE-352Cross-Site Request Forgery (CSRF)CWE-284Improper Access ControlCWE-200Exposure of Sensitive Information to an Unauthorized Actor

Risk Scores

CVSS 3.1
4.3/10
Medium · CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N

Affected Products

VendorProductVersionsPlatforms
Splunkvers:unknown/cloud <9.3.2411.107
Splunkvers:unknown/cloud <9.2.2406.121
Splunkvers:unknown/9.3|<9.3.5
Splunkvers:unknown/9.4|<9.4.3
Splunkvers:unknown/9.1|<9.1.10
Splunkvers:unknown/cloud <9.3.2408.117
Splunkvers:unknown/9.2|<9.2.7

References

advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory

Browse GCVE Records

482 records in the GCVE database · Updated August 26, 2026

No matching records found.

Explore Further

Investigate this vulnerability in the interactive console or download the raw GCVE record.

$ Console Community · 100/wk Open console ›