CVE-2010-3322

Severity CVSS v4.0:
Pending analysis
Type:
CWE-611 Improper Restriction of XML External Entity Reference ('XXE')
Publication date:
14/09/2010
Last modified:
11/04/2025

Description

The XML parser in Splunk 4.0.0 through 4.1.4 allows remote authenticated users to obtain sensitive information and gain privileges via an XML External Entity (XXE) attack to unknown vectors.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:splunk:splunk:*:*:*:*:*:*:*:* 4.0 (including) 4.1.4 (including)