CVE-2022-32155

In universal forwarder versions before 9.0, management services are available remotely by default. When not required, it introduces a potential exposure, but it is not a vulnerability. If exposed, we recommend each customer assess the potential severity specific to your environment. In 9.0, the universal forwarder now binds the management port to localhost preventing remote logins by default. If management services are not required in versions before 9.0, set disableDefaultPort = true in server.conf OR allowRemoteLogin = never in server.conf OR mgmtHostPort = localhost in web.conf. See Configure universal forwarder management security (https://docs.splunk.com/Documentation/Splunk/9.0.0/Security/EnableTLSCertHostnameValidation#Configure_universal_forwarder_management_security) for more information on disabling the remote management services.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:splunk:splunk:*:*:*:*:enterprise:*:*:*
cpe:2.3:a:splunk:splunk_cloud_platform:*:*:*:*:*:*:*:*

History

24 Jun 2022, 01:21

Type Values Removed Values Added
References (CONFIRM) https://docs.splunk.com/Documentation/Splunk/9.0.0/Security/EnableTLSCertHostnameValidation#Configure_universal_forwarder_management_security - (CONFIRM) https://docs.splunk.com/Documentation/Splunk/9.0.0/Security/EnableTLSCertHostnameValidation#Configure_universal_forwarder_management_security - Mitigation, Vendor Advisory
References (CONFIRM) https://docs.splunk.com/Documentation/Splunk/9.0.0/Security/Updates - (CONFIRM) https://docs.splunk.com/Documentation/Splunk/9.0.0/Security/Updates - Release Notes, Vendor Advisory
References (CONFIRM) https://www.splunk.com/en_us/product-security/announcements/svd-2022-0605.html - (CONFIRM) https://www.splunk.com/en_us/product-security/announcements/svd-2022-0605.html - Vendor Advisory
CPE cpe:2.3:a:splunk:splunk:*:*:*:*:enterprise:*:*:*
cpe:2.3:a:splunk:splunk_cloud_platform:*:*:*:*:*:*:*:*
CWE CWE-732
First Time Splunk
Splunk splunk Cloud Platform
Splunk splunk
CVSS v2 : unknown
v3 : unknown
v2 : 5.0
v3 : 7.5

15 Jun 2022, 17:15

Type Values Removed Values Added
New CVE

Information

Published : 2022-06-15 17:15

Updated : 2023-12-10 14:22


NVD link : CVE-2022-32155

Mitre link : CVE-2022-32155

CVE.ORG link : CVE-2022-32155


JSON object : View

Products Affected

splunk

  • splunk_cloud_platform
  • splunk
CWE
CWE-732

Incorrect Permission Assignment for Critical Resource