Show plain JSON{"dataType": "CVE_RECORD", "dataVersion": "5.1", "cveMetadata": {"cveId": "CVE-2022-43567", "assignerOrgId": "42b59230-ec95-491e-8425-5a5befa1a469", "state": "PUBLISHED", "assignerShortName": "Splunk", "requesterUserId": "d03a2723-f9e2-46d2-8173-16ee7d33f715", "dateReserved": "2022-10-20T18:37:09.182Z", "datePublished": "2022-11-04T22:21:50.819Z", "dateUpdated": "2025-05-05T20:34:05.121Z"}, "containers": {"cna": {"affected": [{"defaultStatus": "affected", "product": "Splunk Enterprise", "vendor": "Splunk", "versions": [{"lessThan": "8.1.12", "status": "affected", "version": "8.1", "versionType": "custom"}, {"lessThan": "8.2.9", "status": "affected", "version": "8.2", "versionType": "custom"}, {"lessThan": "9.0.2", "status": "affected", "version": "9.0", "versionType": "custom"}]}], "credits": [{"lang": "en", "type": "finder", "user": "00000000-0000-4000-9000-000000000000", "value": "Danylo Dmytriiev (DDV_UA)"}], "datePublic": "2022-11-02T16:00:00.000Z", "descriptions": [{"lang": "en", "supportingMedia": [{"base64": false, "type": "text/html", "value": "<span style=\"background-color: rgb(255, 255, 255);\">In Splunk Enterprise versions below 8.2.9, 8.1.12, and 9.0.2, an authenticated user can run arbitrary operating system commands remotely through the use of specially crafted requests to the mobile alerts feature in the Splunk Secure Gateway app.</span><br>"}], "value": "In Splunk Enterprise versions below 8.2.9, 8.1.12, and 9.0.2, an authenticated user can run arbitrary operating system commands remotely through the use of specially crafted requests to the mobile alerts feature in the Splunk Secure Gateway app.\n"}], "metrics": [{"cvssV3_1": {"attackComplexity": "LOW", "attackVector": "NETWORK", "availabilityImpact": "HIGH", "baseScore": 8.8, "baseSeverity": "HIGH", "confidentialityImpact": "HIGH", "integrityImpact": "HIGH", "privilegesRequired": "LOW", "scope": "UNCHANGED", "userInteraction": "NONE", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H", "version": "3.1"}, "format": "CVSS", "scenarios": [{"lang": "en", "value": "GENERAL"}]}], "problemTypes": [{"descriptions": [{"cweId": "CWE-502", "description": "CWE-502 Deserialization of Untrusted Data", "lang": "en", "type": "CWE"}]}], "providerMetadata": {"orgId": "42b59230-ec95-491e-8425-5a5befa1a469", "shortName": "Splunk", "dateUpdated": "2022-11-04T22:21:50.819Z"}, "references": [{"url": "https://www.splunk.com/en_us/product-security/announcements/svd-2022-1107.html"}, {"url": "https://research.splunk.com/application/baa41f09-df48-4375-8991-520beea161be/"}], "source": {"advisory": "SVD-2022-1107", "discovery": "EXTERNAL"}, "title": "Remote Code Execution via the Splunk Secure Gateway application Mobile Alerts feature"}, "adp": [{"providerMetadata": {"orgId": "af854a3a-2127-422b-91ae-364da2661108", "shortName": "CVE", "dateUpdated": "2024-08-03T13:32:59.758Z"}, "title": "CVE Program Container", "references": [{"url": "https://www.splunk.com/en_us/product-security/announcements/svd-2022-1107.html", "tags": ["x_transferred"]}, {"url": "https://research.splunk.com/application/baa41f09-df48-4375-8991-520beea161be/", "tags": ["x_transferred"]}]}, {"metrics": [{"other": {"type": "ssvc", "content": {"timestamp": "2025-05-05T20:33:23.307535Z", "id": "CVE-2022-43567", "options": [{"Exploitation": "none"}, {"Automatable": "no"}, {"Technical Impact": "total"}], "role": "CISA Coordinator", "version": "2.0.3"}}}], "title": "CISA ADP Vulnrichment", "providerMetadata": {"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0", "shortName": "CISA-ADP", "dateUpdated": "2025-05-05T20:34:05.121Z"}}]}}