SB2017112909 - Multiple vulnerabilities in Splunk Enterprise
Published: November 29, 2017
Security Bulletin ID
SB2017112909
Severity
Low
Patch available
YES
Number of vulnerabilities
1
Exploitation vector
Remote access
Highest impact
Data manipulation
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Improper access control (CVE-ID: CVE-2017-17067)
The vulnerability allows a remote authenticated attacker to impersonate a targeted user of the targeted system.The weakness exists in the Security Assertion Markup Language (SAML) implementation due to unknown error. A remote attacker can access a SAML-enabled Splunk Web, impersonate a targeted user and perform arbitrary actions.
Remediation
Install update from vendor's website.