Files
splunk-security_content/stories/splunk_enterprise_vulnerability.yml
Patrick Bareiss 7cbc9a9ba6 WIP
2020-04-30 10:34:18 +02:00

44 lines
1.6 KiB
YAML

name: Splunk Enterprise Vulnerability
id: 4e692b96-de2d-4bd1-9105-37e2368a8db1
version: 1
date: '2017-09-19'
description: Keeping your Splunk deployment up to date is critical and may help you
reduce the risk of CVE-2016-4859, an open-redirection vulnerability within some
older versions of Splunk Enterprise. The detection search will help ensure that
users are being properly authenticated and not being redirected to malicious domains.
narrative: 'This Analytic Story is associated with CVE-2016-4859, an open-redirect
vulnerability in the following versions of Splunk Enterprise:\
\
1. Splunk Enterprise 6.4.x, prior to 6.4.3\
1. Splunk Enterprise 6.3.x, prior to 6.3.6\
1. Splunk Enterprise 6.2.x, prior to 6.2.10\
1. Splunk Enterprise 6.1.x, prior to 6.1.11\
1. Splunk Enterprise 6.0.x, prior to 6.0.12\
1. Splunk Enterprise 5.0.x, prior to 5.0.16\
1. Splunk Light, prior to 6.4.3CVE-2016-4859 allows attackers to redirect users
to arbitrary web sites and conduct phishing attacks via unspecified vectors. (Credit:
Noriaki Iwasaki, Cyber Defense Institute, Inc.).\
It is important to ensure that your Splunk deployment is being kept up to date and
is properly configured. This detection search allows analysts to monitor internal
logs to ensure users are properly authenticated and cannot be redirected to any
malicious third-party websites.'
author: Bhavin Patel, Splunk
type: ESCU
references:
- http://www.splunk.com/view/SP-CAAAPQ6#announce
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-4859
tags:
analytics_story: Splunk Enterprise Vulnerability
usecase: Security Monitoring
category:
- Vulnerability