Splunk Enterprise Multiple Version Information Disclosure

Discussion in 'News Aggregator' started by Packet Storm, 4 Apr 2017.

  1. Packet Storm

    Packet Storm Guest

    Attackers can siphon information from Splunk Enterprise if an authenticated Splunk user visits a malicious webpage. Some useful data gained is the currently logged in username and if remote user setting is enabled. After, the username can be use to Phish or Brute Force Splunk Enterprise login. Additional information stolen may aid in furthering attacks.

    Continue reading...
     

Share This Page

Loading...