Vulnerability Database

324,292

Total vulnerabilities in the database

CVE-2017-12572

Persistent Cross Site Scripting (XSS) exists in Splunk Enterprise 6.5.x before 6.5.2, 6.4.x before 6.4.6, and 6.3.x before 6.3.9 and Splunk Light before 6.5.2, with exploitation requiring administrative access, aka SPL-134104.

  • Published: Aug 5, 2017
  • Updated: Nov 9, 2025
  • CVE: CVE-2017-12572
  • Severity: Low
  • Exploit:

CVSS v2:

  • Severity: Low
  • Score: 3.5
  • AV:N/AC:M/Au:S/C:N/I:P/A:N
Software From Fixed in
splunk / splunk 6.5.0 6.5.0.x
splunk / splunk 6.3.8 6.3.8.x
splunk / splunk 6.3.4 6.3.4.x
splunk / splunk 6.4.4 6.4.4.x
splunk / splunk 6.3.5 6.3.5.x
splunk / splunk 6.4.1 6.4.1.x
splunk / splunk 6.4.0 6.4.0.x
splunk / splunk 6.3.0 6.3.0.x
splunk / splunk 6.5.1 6.5.1.x
splunk / splunk 6.3.3 6.3.3.x
splunk / splunk 6.4.3 6.4.3.x
splunk / splunk 6.3.7 6.3.7.x
splunk / splunk 6.4.5 6.4.5.x
splunk / splunk 6.4.2 6.4.2.x
splunk / splunk 6.3.6 6.3.6.x
splunk / splunk 6.3.1 6.3.1.x
splunk / splunk 6.3.2 6.3.2.x