CVE-2014-5197: Splunk
Medium severity, CVSS 4.0. EPSS: 2.2% chance of exploitation in the next 30 days.
Directory traversal vulnerability in (1) Splunk Web or the (2) Splunkd HTTP Server in Splunk Enterprise 6.1.x before 6.1.3 allows remote authenticated users to read arbitrary files via a .. (dot dot) in a URI, related to search ids.
Affected products
- Splunk Splunk: version 6.1 only; version 6.1.1 only; version 6.1.2 only
Published 2014-08-12. Last modified 2026-06-17.