CyberRota Analysis
AI-GeneratedIn Splunk Enterprise versions prior to 10.4.2, 10.2.6, 10.0.9, and 9.4.14, non-admin users can exploit a vulnerability in the Data Orchestration jobs endpoint to execute arbitrary SQL queries, potentially accessing sensitive data, including jobs and credentials belonging to other users. This flaw arises from the lack of parameterized queries, allowing unauthorized data access. Organizations using affected versions should prioritize patching to mitigate the risk of data exposure.
Original NVD Description
In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, a user who does not hold the "admin" or "power" Splunk roles could execute attacker-chosen Structured Query Language (SQL) queries through the Data Orchestration jobs endpoint, allowing for access to substantially all data stored by Data Orchestration, including jobs owned by other users and stored connection credentials. The vulnerability is possible because Data Orchestration builds a database query from user-controlled job filter values without using parameterized queries. For more information see About configuring role-based user access (https://help.splunk.com/en/splunk-enterprise/administer/manage-users-and-security/10.2/manage-splunk-platform-users-and-roles/about-configuring-role-based-user-access) in the Splunk documentation.
Related CVEs
Other vulnerabilities affecting the same vendor(s)