Skip to content
VulniPulse

Splunk ES / ITSI / SOAR Vulnerabilities & Security Advisories

5 advisories tracked · Splunk (prodsec@splunk.com CNA) via NVD · 0 listed in the CISA Known Exploited Vulnerabilities catalog

Every row below is a published Splunk advisory that VulniPulse classified as ES / ITSI / SOAR, with the CVEs, affected and fixed releases and exploitation status the vendor stated. Severity mix: 2 high, 3 medium.

Android app · Google Play

Monitor Splunk CVEs from your phone.

Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.

Source

Splunk (prodsec@splunk.com CNA) via NVD

Splunk is its own CVE Numbering Authority. VulniPulse ingests Splunk's CVEs from the NVD CNA feed (prodsec@splunk.com), each linking to its SVD-YYYY-NNNN advisory on advisory.splunk.com. Covers Splunk Enterprise, Splunk Cloud Platform, the Universal Forwarder, IT Service Intelligence (ITSI), SOAR, Enterprise Security and Splunk apps/add-ons — the SIEM at the centre of most SOCs, so a security-team audience that patches on advisory day.

Latest Splunk ES / ITSI / SOAR advisories

Medium6.4Splunk

Medium [CVE-2025-22621] In versions 1.0.67 and lower of the Splunk App for SOAR, the Splunk documentation for that app recommended adding the…

In versions 1.0.67 and lower of the Splunk App for SOAR, the Splunk documentation for that app recommended adding the `admin_all_objects` capability to the `splunk_app_soar` role. This addition could lead to improper access control for a low-privileged user that does not hold the "admin" Splunk roles.

CVE-2025-22621
ES / ITSI / SOAR
Jan 7, 2025
Medium6.5Splunk

Medium [CVE-2024-22165] In Splunk Enterprise Security (ES) versions lower than 7.1.2, an attacker

In Splunk Enterprise Security (ES) versions lower than 7.1.2, an attacker can create a malformed Investigation to perform a denial of service (DoS). The malformed investigation prevents the generation and rendering of the Investigations manager until it is deleted. The vulnerability requires an authenticated session and access to create an Investigation. It only affects the availability of the Investigations manager, but without the manager, the Investigations functionality becomes unusable for most users.

CVE-2024-22165
Splunk EnterpriseES / ITSI / SOAR
Jan 9, 2024
Medium4.3Splunk

Medium [CVE-2024-22164] In Splunk Enterprise Security (ES) versions below 7.1.2, an attacker

In Splunk Enterprise Security (ES) versions below 7.1.2, an attacker can use investigation attachments to perform a denial of service (DoS) to the Investigation. The attachment endpoint does not properly limit the size of the request which lets an attacker cause the Investigation to become inaccessible.

CVE-2024-22164
Splunk EnterpriseES / ITSI / SOAR
Jan 9, 2024

← All Splunk advisories