Splunk Enterprise 6.2.2 addresses two vulnerabilities
Advisory ID: SP-CAAANV8
CVE ID: -
Published: 2015-02-23
Last Update: 2015-02-23
CVSSv3.1 Score: -, High
CVSSv3.1 Vector: -
CWE: -
Bug ID: SPL-95203, SPL-93754
Description
Splunk Enterprise version 6.2.2 addresses two vulnerabilities
- Multiple vulnerabilities in OpenSSL prior to 1.0.1k (SPL-95203, CVE-2014-3572, CVE-2015-0204)
- Splunk Web crashes due to specific HTTP requests (SPL-93754)
At the time of this announcement, Splunk is not aware of any cases where these vulnerabilities have been actively exploited. Previous Product Security Announcements can be found on our Splunk Product Security Portal. Use SPL numbers when referencing issues in communication with Splunk. If there is no CVE Identifier listed with a vulnerability, it will be added once it is assigned by a CVE Numbering Authority. To standardize the calculation of severity scores for each vulnerability, when appropriate, Splunk uses Common Vulnerability Scoring System version 2.
Affected Products and Components
These vulnerabilities affect all versions of Splunk Enterprise 6.2.* before 6.2.2:
- Multiple vulnerabilities in OpenSSL prior to 1.0.1k (SPL-95203, CVE-2014-3572, CVE-2015-0204)
- This does affect: All Splunk Enterprise components.
- Splunk Web crashes due to specific HTTP requests (SPL-93754)
- This does not affect: Universal Forwarders.
- This does affect: Search heads, Heavy Forwarders with UI turned on, and Indexers with UI turned on.
Mitigation and Upgrades
To mitigate these issues, Splunk recommends upgrading to the latest release and applying as many of the Hardening Standards from the Securing Splunk documentation as are relevant to your environment. Splunk Enterprise releases are cumulative, meaning that future releases will contain fixes to these vulnerabilities, new features and other bug fixes.
Vulnerability Descriptions and Ratings
Multiple vulnerabilities in OpenSSL prior to 1.0.1k (SPL-95203, CVE-2014-3572, CVE-2015-0204)
Description: OpenSSL versions prior to 1.0.1k do not properly validate session parameters. These vulnerabilities could cause a Splunk instance communicating with malicious server to not properly use ephemeral keys (CVE-2014-3572) or use weaker RSA keys (CVE-2015-0204).
CVSS Severity (version 2.0):
CVSS Base Score 3.6
CVSS Impact Subscore 4.9
CVSS Exploitability Subscore 3.9
Overall CVSS Score 3.6
Splunk Web crashes due to specific HTTP requests (SPL-93754)
Description: When Splunk Web receives specific HTTP requests, an assert is triggered causing the Splunk Enterprise instance to crash. All Splunk services on the system running Splunk Web halt until Splunk Enterprise is restarted.
CVSS Severity (version 2.0):
CVSS Base Score 7.8
CVSS Impact Subscore 6.9
CVSS Exploitability Subscore 10
Overall CVSS Score 7.8
Document History
- 2015-Feb-23: Rev 1. Initial Release