Splunk Enterprise
cpe:2.3:a:splunk:splunk:*:*:*:*:*:*:*
- >= 9.4.0, <= 9.4.2
- >= 9.3.0, <= 9.3.4
- >= 9.2.0, <= 9.2.6
- >= 9.1.0, <= 9.1.9
A vulnerability exists in Splunk Enterprise versions prior to 9.4.3, 9.3.5, 9.2.7, and 9.1.10, allowing low-privileged users without 'admin' or 'power' roles to disable the scheduled 'Bucket Copy Trigger' search in the Splunk Archiver application. This issue arises from inadequate access controls on saved searches within the app.
Exploitation of this vulnerability allows low-privileged users to disable a scheduled search, potentially disrupting data management processes that rely on the 'Bucket Copy Trigger' functionality.
Users can upgrade to Splunk Enterprise versions 9.4.3, 9.3.5, 9.2.7, 9.1.10, or higher. Alternatively, the Splunk Archiver app can be disabled without impacting other functionalities.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.