Third-Party Package Updates in Splunk AppDynamics Analytics Agent - October 2025

Advisory ID: SVD-2025-1010

CVE ID:  Multiple

Published: 2025-10-29

Last Update: 2025-10-29

Description

Splunk remedied common vulnerabilities and exposures (CVEs) in Third Party Packages in Splunk AppDynamics Analytics Agent version 25.7.0 and higher, including the following:

PackageRemediationCVESeverity
jetty_jetty-httpUpgraded to 12.0.22CVE-2024-6763Medium
opensslUpgraded to 3.0.6CVE-2022-3358High
Apache commons-fileuploadUpgraded to 1.6.0CVE-2025-48976High

Solution

Upgrade Splunk AppDynamics Analytics Agent to versions 25.7.0 or higher.

Product Status

ProductBase VersionAffected VersionFix Version
Splunk AppDynamics Analytics Agent25.7.0Below 25.7.025.7.0

Severity

For the CVEs in this list, Splunk adopted the vendor’s severity rating or the National Vulnerability Database (NVD) common vulnerability scoring system (CVSS) rating, as available.