CVE-2018-7432: Splunk
High severity, CVSS 7.5. EPSS: 2.3% chance of exploitation in the next 30 days.
Splunk Enterprise 6.2.x before 6.2.14, 6.3.x before 6.3.10, 6.4.x before 6.4.7, and 6.5.x before 6.5.3; and Splunk Light before 6.6.0 allow remote attackers to cause a denial of service via a crafted HTTP request.
Affected products
- Splunk Splunk: before 6.6.0 (fixed in 6.6.0); from 6.2.0, before 6.2.14 (fixed in 6.2.14); from 6.3.0, before 6.3.10 (fixed in 6.3.10); from 6.4.0, before 6.4.7 (fixed in 6.4.7); from 6.5.0, before 6.5.3 (fixed in 6.5.3)
Published 2018-10-23. Last modified 2026-06-17.