Known vulnerabilities in Splunk Security Orchestration, Automation and Response (SOAR) - page 2

Software CPE: cpe:2.3:a:splunk:soar:*:*:*:*:*:*:*:*
Total vulnerabilities: 32
Public exploits: 1
Known exploited (KEV): 0
Highest CVSSv4 Score: 9.2

Breakdown by Severity Chart

Severity distribution of vulnerabilities affecting Splunk Security Orchestration, Automation and Response (SOAR) Splunk Security Orchestration, Automation and Response (SOAR) is affected by 32 known vulnerabilities: 5 high, 8 medium, 19 low Critical High Medium Low

Vulnerabilities (32)

Vulnerability CWE-ID CSH Severity Public Exploit KEV First fixed release Published Bulletins
#VU116130 - Improper input validation
CVE-2025-9288
CWE-20 Medium
No
No
7.1.0 26.09.2025 SB2025092616
SB2025092618
SB2025092620
and 17 more
#VU115762 - Improper input validation
CVE-2025-9287
CWE-20 Medium
No
No
7.1.0 18.09.2025 SB2025091827
SB2025091828
SB2025091830
and 12 more
#VU114450 - Loop with Unreachable Exit Condition ('Infinite Loop')
CVE-2025-57810
CWE-835 Medium
No
No
7.1.0 27.08.2025 SB2025082720
SB2025100912
SB2025112543
and 4 more
#VU112890 - Inefficient Regular Expression Complexity
CVE-2025-5889
CWE-1333 Low
No
No
7.1.0 15.07.2025 SB2025071511
SB2025071512
SB2025071513
and 33 more
#VU111716 - Insufficiently Protected Credentials
CVE-2024-47081
CWE-522 Medium
No
No
7.1.0 21.06.2025 SB2025062111
SB2025062112
SB2025062113
and 95 more
#VU109840 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CVE-2025-47273
CWE-22 High
No
No
7.0.0 27.05.2025 SB2025052721
SB2025052734
SB2025052736
and 112 more
#VU108774 - Resource exhaustion
CVE-2025-32873
CWE-400 Medium
No
No
7.1.0 07.05.2025 SB2025050779
SB2025050787
SB2025050789
and 14 more
#VU105984 - Inefficient Regular Expression Complexity
CVE-2025-27789
CWE-1333 Low
No
No
7.0.0 24.03.2025 SB2025032476
SB2025041020
SB2025041691
and 45 more
#VU101972 - Security Features
CVE-2024-56326
CWE-254 Low
No
No
7.0.0 27.12.2024 SB2024122789
SB2024122790
SB2024122791
and 78 more
#VU78799 - Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
CVE-2023-3997
CWE-78 High
No
No
6.1.0 31.07.2023 SB2023073163
#VU72036 - Error Handling
CVE-2023-23931
CWE-388 Low
No
No
41.0.1 08.02.2023 SB2023020813
SB2023030952
SB2023031419
and 68 more
#VU71992 - Type confusion
CVE-2023-0286
CWE-843 High
No
No
41.0.1 07.02.2023 SB2023020742
SB2023020747
SB2023020748
and 223 more


Showing elements 21 - 40 out of 32