CVE-2017-12572: Splunk

Medium severity, CVSS 4.8. EPSS: 0.5% chance of exploitation in the next 30 days.

Persistent Cross Site Scripting (XSS) exists in Splunk Enterprise 6.5.x before 6.5.2, 6.4.x before 6.4.6, and 6.3.x before 6.3.9 and Splunk Light before 6.5.2, with exploitation requiring administrative access, aka SPL-134104.

Affected products

  • Splunk Splunk: version 6.3.0 only; version 6.3.1 only; version 6.3.2 only; version 6.3.3 only; version 6.3.4 only; version 6.3.5 only; …

Published 2017-08-05. Last modified 2026-06-17.