Cross-Site Scripting Vulnerability in Splunk Enterprise by Splunk
CVE-2016-4858
4.8MEDIUM
What is CVE-2016-4858?
This vulnerability in Splunk Enterprise and Splunk Light allows remote attackers to inject arbitrary web scripts or HTML into web pages through unspecified vectors, potentially compromising sensitive data and user sessions. Affected versions span from 5.0.x to 6.4.x, necessitating timely updates to secure systems against this exploitable flaw.
Affected Version(s)
Splunk Enterprise 6.4.x prior to 6.4.2
Splunk Enterprise 6.3.x prior to 6.3.6
Splunk Enterprise 6.2.x prior to 6.2.10