In Splunk Enterprise versions below 9.2.2, 9.1.5, and 9.0.10 on Windows, an authenticated user could execute a specially crafted query that they could then use to serialize untrusted data. The attacker could use the query to execute arbitrary code.
History

Fri, 07 Mar 2025 17:30:00 +0000

Type Values Removed Values Added
First Time appeared Splunk splunk
CPEs cpe:2.3:a:splunk:splunk:*:*:*:*:enterprise:*:*:*
Vendors & Products Splunk splunk

Tue, 04 Mar 2025 03:45:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:a:splunk:enterprise_security:9.0:*:*:*:*:*:*:*
cpe:2.3:a:splunk:enterprise_security:9.1:*:*:*:*:*:*:*
cpe:2.3:a:splunk:enterprise_security:9.2:*:*:*:*:*:*:*
cpe:2.3:a:splunk:enterprise_security:*:*:*:*:*:*:*:*
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'total'}, 'version': '2.0.3'}


cve-icon MITRE

Status: PUBLISHED

Assigner: Splunk

Published: 2024-07-01T16:30:44.270Z

Updated: 2025-02-28T11:03:53.978Z

Reserved: 2024-05-30T16:36:20.999Z

Link: CVE-2024-36984

cve-icon Vulnrichment

Updated: 2024-08-02T03:43:50.601Z

cve-icon NVD

Status : Analyzed

Published: 2024-07-01T17:15:06.480

Modified: 2025-03-07T16:48:11.150

Link: CVE-2024-36984

cve-icon Redhat

No data.