Vulnerability Database

289,782

Total vulnerabilities in the database

CVE-2017-12572

Persistent Cross Site Scripting (XSS) exists in Splunk Enterprise 6.5.x before 6.5.2, 6.4.x before 6.4.6, and 6.3.x before 6.3.9 and Splunk Light before 6.5.2, with exploitation requiring administrative access, aka SPL-134104.

  • Published: Aug 5, 2017
  • Updated: Apr 13, 2023
  • CVE: CVE-2017-12572
  • Severity: Low
  • Exploit:

CVSS v3:

  • Severity: Low
  • Score: 4.8
  • AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N

CVSS v2:

  • Severity: Low
  • Score: 3.5
  • AV:N/AC:M/Au:S/C:N/I:P/A:N
Software From Fixed in
splunk / splunk 6.5.0 6.5.0.x
splunk / splunk 6.3.8 6.3.8.x
splunk / splunk 6.3.4 6.3.4.x
splunk / splunk 6.4.4 6.4.4.x
splunk / splunk 6.3.5 6.3.5.x
splunk / splunk 6.4.1 6.4.1.x
splunk / splunk 6.4.0 6.4.0.x
splunk / splunk 6.3.0 6.3.0.x
splunk / splunk 6.5.1 6.5.1.x
splunk / splunk 6.3.3 6.3.3.x
splunk / splunk 6.4.3 6.4.3.x
splunk / splunk 6.3.7 6.3.7.x
splunk / splunk 6.4.5 6.4.5.x
splunk / splunk 6.4.2 6.4.2.x
splunk / splunk 6.3.6 6.3.6.x
splunk / splunk 6.3.1 6.3.1.x
splunk / splunk 6.3.2 6.3.2.x