CVE-2010-2502

Published Jun 28, 2010

Last updated 14 years ago

Overview

Description
Multiple directory traversal vulnerabilities in Splunk 4.0 through 4.0.10 and 4.1 through 4.1.1 allow (1) remote attackers to read arbitrary files, aka SPL-31194; (2) remote authenticated users to modify arbitrary files, aka SPL-31063; or (3) have an unknown impact via redirects, aka SPL-31067.
Source
cve@mitre.org
NVD status
Analyzed

Social media

Hype score
Not currently trending

Risk scores

CVSS 2.0

Type
Primary
Base score
7.5
Impact score
8.5
Exploitability score
6.8
Vector string
AV:N/AC:M/Au:S/C:C/I:P/A:P

Weaknesses

nvd@nist.gov
CWE-22

Evaluator

Comment
Per: http://www.splunk.com/view/SP-CAAAFGD 'Splunk recommends that customers only apply the patch as a last resort, in situations where they are unable to upgrade immediately.'
Impact
-
Solution
-

Configurations