CVE-2016-10126

Splunk Web in Splunk Enterprise 5.0.x before 5.0.17, 6.0.x before 6.0.13, 6.1.x before 6.1.12, 6.2.x before 6.2.12, 6.3.x before 6.3.8, and 6.4.x before 6.4.4 allows remote attackers to conduct HTTP request injection attacks and obtain sensitive REST API authentication-token information via unspecified vectors, aka SPL-128840.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
9.8 CRITICAL
NETWORK
LOW
NONE
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Base Score
CVSS 3.x
EPSS Score
Percentile: Unknown
Affected Products (NVD)
VendorProductVersion
splunksplunk
5.0.0
splunksplunk
5.0.1
splunksplunk
5.0.2
splunksplunk
5.0.3
splunksplunk
5.0.4
splunksplunk
5.0.5
splunksplunk
5.0.6
splunksplunk
5.0.7
splunksplunk
5.0.8
splunksplunk
5.0.9
splunksplunk
5.0.10
splunksplunk
5.0.11
splunksplunk
5.0.12
splunksplunk
5.0.13
splunksplunk
5.0.14
splunksplunk
5.0.15
splunksplunk
5.0.16
splunksplunk
6.0.0
splunksplunk
6.0.1
splunksplunk
6.0.2
splunksplunk
6.0.3
splunksplunk
6.0.4
splunksplunk
6.0.5
splunksplunk
6.0.6
splunksplunk
6.0.7
splunksplunk
6.0.8
splunksplunk
6.0.9
splunksplunk
6.0.10
splunksplunk
6.0.11
splunksplunk
6.0.12
splunksplunk
6.1.0
splunksplunk
6.1.1
splunksplunk
6.1.2
splunksplunk
6.1.3
splunksplunk
6.1.4
splunksplunk
6.1.5
splunksplunk
6.1.6
splunksplunk
6.1.7
splunksplunk
6.1.8
splunksplunk
6.1.9
splunksplunk
6.1.10
splunksplunk
6.1.11
splunksplunk
6.2.0
splunksplunk
6.2.1
splunksplunk
6.2.2
splunksplunk
6.2.3
splunksplunk
6.2.4
splunksplunk
6.2.5
splunksplunk
6.2.6
splunksplunk
6.2.7
splunksplunk
6.2.8
splunksplunk
6.2.9
splunksplunk
6.2.10
splunksplunk
6.2.11
splunksplunk
6.3.0
splunksplunk
6.3.1
splunksplunk
6.3.2
splunksplunk
6.3.3
splunksplunk
6.3.4
splunksplunk
6.3.5
splunksplunk
6.3.6
splunksplunk
6.3.7
splunksplunk
6.4.0
splunksplunk
6.4.1
splunksplunk
6.4.2
splunksplunk
6.4.3
𝑥
= Vulnerable software versions
Common Weakness Enumeration