CVE-2024-36984
Remote Code Execution through Serialized Session Payload in Splunk Enterprise on Windows
Severity
High 8.8
CVSS 3.1
Exploited
Not listed
EPSS
0.014
70.6th percentile
Discovered by
Not disclosed
Published
Jul 1, 2024
Assigned by splunk
Description
In Splunk Enterprise versions below 9.2.2, 9.1.5, and 9.0.10 on Windows, an authenticated user could execute a specially crafted query that they could then use to serialize untrusted data. The attacker could use the query to execute arbitrary code.
Weakness: CWE-502
Affected products
| Vendor | Product | Category | Matched by |
|---|---|---|---|
| Cisco | Splunk Enterprise | SIEM & Log Management | affected-vendor |
| Cisco | Splunk Enterprise Security | SIEM & Log Management | affected-vendor |
Vendor-reported products (2)
- Splunk · Splunk Enterprise
- splunk · enterprise_security
Credit
Danylo Dmytriiev (DDV_UA)