Known vulnerabilities in Splunk Enterprise Security (ES) 7.0.1
Vendor:
Splunk Inc.
Software:
Splunk Enterprise Security (ES)
Version:
7.0.1
Software CPE:
cpe:2.3:a:splunk:es:*:*:*:*:*:*:*:*
Website:
https://www.splunk.com/
Total vulnerabilities:
9
Public exploits:
0
Known exploited (KEV):
0
Highest CVSSv4 Score:
9.3
Vulnerabilities by Severity
Vulnerabilities (9)
| Vulnerability | CWE-ID | CSH Severity | Public Exploit | KEV | First fixed release | Published | Bulletins |
|---|---|---|---|---|---|---|---|
| #VU85200 - Resource Management Errors CVE-2024-22165 |
CWE-399 | Low | 7.1.2, 7.2.0, 7.3.0 | 09.01.2024 |
SB2024010964 |
||
| #VU85199 - Resource exhaustion CVE-2024-22164 |
CWE-400 | Medium | 7.1.2, 7.2.0, 7.3.0 | 09.01.2024 |
SB2024010964 |
||
| #VU85172 - Incorrect Regular Expression CVE-2021-23446 |
CWE-185 | Medium | 7.1.2, 7.2.0, 7.3.0 | 09.01.2024 |
SB2021092928 SB2024010965 |
||
| #VU83234 - Incorrect Comparison CVE-2023-45133 |
CWE-697 | Low | 7.1.2, 7.2.0, 7.3.0 | 17.11.2023 |
SB2023111710 SB2023111712 SB2023113028 and 26 more |
||
| #VU78932 - Incorrect Regular Expression CVE-2022-25883 |
CWE-185 | Medium | 7.1.2, 7.2.0, 7.3.0 | 03.08.2023 |
SB2023080361 SB2023080362 SB2023081514 and 73 more |
||
| #VU71577 - Improper Control of Generation of Code ('Code Injection') CVE-2022-46175 |
CWE-94 | Medium | 7.1.2, 7.2.0, 7.3.0 | 26.01.2023 |
SB2023012644 SB2023012645 SB2023013117 and 46 more |
||
| #VU70123 - Improper Control of Generation of Code ('Code Injection') CVE-2022-37601 |
CWE-94 | High | 7.1.2, 7.2.0, 7.3.0 | 12.12.2022 |
SB2022121220 SB2023010419 SB2023011403 and 20 more |
||
| #VU70122 - Incorrect Regular Expression CVE-2022-37599 |
CWE-185 | Medium | 7.1.2, 7.2.0, 7.3.0 | 12.12.2022 |
SB2022121221 SB2023010424 SB2023020920 and 19 more |
||
| #VU70121 - Incorrect Regular Expression CVE-2022-37603 |
CWE-185 | Medium | 7.1.2, 7.2.0, 7.3.0 | 12.12.2022 |
SB2022121221 SB2022121222 SB2023010418 and 29 more |