CVE-2010-2502

Published Jun 28, 2010

Last updated 3 months ago

Overview

Description
Multiple directory traversal vulnerabilities in Splunk 4.0 through 4.0.10 and 4.1 through 4.1.1 allow (1) remote attackers to read arbitrary files, aka SPL-31194; (2) remote authenticated users to modify arbitrary files, aka SPL-31063; or (3) have an unknown impact via redirects, aka SPL-31067.
Source
cve@mitre.org
NVD status
Modified

Risk scores

CVSS 2.0

Type
Primary
Base score
7.5
Impact score
8.5
Exploitability score
6.8
Vector string
AV:N/AC:M/Au:S/C:C/I:P/A:P

Weaknesses

nvd@nist.gov
CWE-22

Social media

Hype score
Not currently trending

Evaluator

Comment
Per: http://www.splunk.com/view/SP-CAAAFGD 'Splunk recommends that customers only apply the patch as a last resort, in situations where they are unable to upgrade immediately.'
Impact
-
Solution
-

Configurations