U.S. flag   An official website of the United States government
Dot gov

Official websites use .gov
A .gov website belongs to an official government organization in the United States.

Https

Secure .gov websites use HTTPS
A lock (Dot gov) or https:// means you've safely connected to the .gov website. Share sensitive information only on official, secure websites.

Vulnerability Change Records for CVE-2017-5607

Change History

Initial Analysis by NIST 4/17/2017 9:26:38 AM

Action Type Old Value New Value
Added CPE Configuration

								
							
							
						
OR
     *cpe:2.3:a:splunk:splunk:5.0:*:*:*:enterprise:*:*:*
     *cpe:2.3:a:splunk:splunk:5.0.15:*:*:*:enterprise:*:*:*
     *cpe:2.3:a:splunk:splunk:5.0.16:*:*:*:enterprise:*:*:*
     *cpe:2.3:a:splunk:splunk:5.0.17:*:*:*:enterprise:*:*:*
     *cpe:2.3:a:splunk:splunk:6.0:*:*:*:enterprise:*:*:*
     *cpe:2.3:a:splunk:splunk:6.0.11:*:*:*:enterprise:*:*:*
     *cpe:2.3:a:splunk:splunk:6.0.12:*:*:*:enterprise:*:*:*
     *cpe:2.3:a:splunk:splunk:6.0.13:*:*:*:enterprise:*:*:*
     *cpe:2.3:a:splunk:splunk:6.0.3:*:*:*:enterprise:*:*:*
     *cpe:2.3:a:splunk:splunk:6.0.4:*:*:*:enterprise:*:*:*
     *cpe:2.3:a:splunk:splunk:6.0.6:*:*:*:enterprise:*:*:*
     *cpe:2.3:a:splunk:splunk:6.1.0:*:*:*:enterprise:*:*:*
     *cpe:2.3:a:splunk:splunk:6.1.1:*:*:*:enterprise:*:*:*
     *cpe:2.3:a:splunk:splunk:6.1.10:*:*:*:enterprise:*:*:*
     *cpe:2.3:a:splunk:splunk:6.1.11:*:*:*:enterprise:*:*:*
     *cpe:2.3:a:splunk:splunk:6.1.12:*:*:*:enterprise:*:*:*
     *cpe:2.3:a:splunk:splunk:6.1.2:*:*:*:enterprise:*:*:*
     *cpe:2.3:a:splunk:splunk:6.1.3:*:*:*:enterprise:*:*:*
     *cpe:2.3:a:splunk:splunk:6.1.4:*:*:*:enterprise:*:*:*
     *cpe:2.3:a:splunk:splunk:6.1.5:*:*:*:enterprise:*:*:*
     *cpe:2.3:a:splunk:splunk:6.1.6:*:*:*:enterprise:*:*:*
     *cpe:2.3:a:splunk:splunk:6.1.7:*:*:*:enterprise:*:*:*
     *cpe:2.3:a:splunk:splunk:6.1.8:*:*:*:enterprise:*:*:*
     *cpe:2.3:a:splunk:splunk:6.1.9:*:*:*:enterprise:*:*:*
     *cpe:2.3:a:splunk:splunk:6.2:*:*:*:enterprise:*:*:*
     *cpe:2.3:a:splunk:splunk:6.2.1:*:*:*:enterprise:*:*:*
     *cpe:2.3:a:splunk:splunk:6.2.10:*:*:*:enterprise:*:*:*
     *cpe:2.3:a:splunk:splunk:6.2.11:*:*:*:enterprise:*:*:*
     *cpe:2.3:a:splunk:splunk:6.2.12:*:*:*:enterprise:*:*:*
     *cpe:2.3:a:splunk:splunk:6.2.13:*:*:*:enterprise:*:*:*
     *cpe:2.3:a:splunk:splunk:6.2.2:*:*:*:enterprise:*:*:*
     *cpe:2.3:a:splunk:splunk:6.2.3:*:*:*:enterprise:*:*:*
     *cpe:2.3:a:splunk:splunk:6.2.4:*:*:*:enterprise:*:*:*
     *cpe:2.3:a:splunk:splunk:6.2.5:*:*:*:enterprise:*:*:*
     *cpe:2.3:a:splunk:splunk:6.2.6:*:*:*:enterprise:*:*:*
     *cpe:2.3:a:splunk:splunk:6.2.7:*:*:*:enterprise:*:*:*
     *cpe:2.3:a:splunk:splunk:6.2.8:*:*:*:enterprise:*:*:*
     *cpe:2.3:a:splunk:splunk:6.2.9:*:*:*:enterprise:*:*:*
     *cpe:2.3:a:splunk:splunk:6.3.0:*:*:*:enterprise:*:*:*
     *cpe:2.3:a:splunk:splunk:6.3.1:*:*:*:enterprise:*:*:*
     *cpe:2.3:a:splunk:splunk:6.3.9:*:*:*:enterprise:*:*:*
     *cpe:2.3:a:splunk:splunk:6.4.0:*:*:*:enterprise:*:*:*
     *cpe:2.3:a:splunk:splunk:6.4.1:*:*:*:enterprise:*:*:*
     *cpe:2.3:a:splunk:splunk:6.4.2:*:*:*:enterprise:*:*:*
     *cpe:2.3:a:splunk:splunk:6.4.3:*:*:*:enterprise:*:*:*
     *cpe:2.3:a:splunk:splunk:6.4.4:*:*:*:enterprise:*:*:*
     *cpe:2.3:a:splunk:splunk:6.4.5:*:*:*:enterprise:*:*:*
     *cpe:2.3:a:splunk:splunk:6.5.0:*:*:*:enterprise:*:*:*
     *cpe:2.3:a:splunk:splunk:6.5.1:*:*:*:enterprise:*:*:*
     *cpe:2.3:a:splunk:splunk:6.5.2:*:*:*:enterprise:*:*:*
Added CPE Configuration

								
							
							
						
OR
     *cpe:2.3:a:splunk:splunk:6.5.1:*:*:*:light:*:*:* (and previous)
Added CVSS V2

								
							
							
						
(AV:N/AC:M/Au:N/C:P/I:N/A:N)
Added CVSS V3

								
							
							
						
AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N
Added CWE

								
							
							
						
CWE-200
Changed Reference Type
http://hyp3rlinx.altervista.org/advisories/SPLUNK-ENTERPRISE-INFORMATION-THEFT.txt No Types Assigned
http://hyp3rlinx.altervista.org/advisories/SPLUNK-ENTERPRISE-INFORMATION-THEFT.txt Exploit, Third Party Advisory
Changed Reference Type
http://seclists.org/fulldisclosure/2017/Mar/89 No Types Assigned
http://seclists.org/fulldisclosure/2017/Mar/89 Exploit, Third Party Advisory
Changed Reference Type
http://www.securityfocus.com/archive/1/archive/1/540346/100/0/threaded No Types Assigned
http://www.securityfocus.com/archive/1/archive/1/540346/100/0/threaded Exploit, Third Party Advisory, VDB Entry
Changed Reference Type
http://www.securityfocus.com/bid/97265 No Types Assigned
http://www.securityfocus.com/bid/97265 Third Party Advisory, VDB Entry
Changed Reference Type
http://www.securityfocus.com/bid/97286 No Types Assigned
http://www.securityfocus.com/bid/97286 Third Party Advisory, VDB Entry
Changed Reference Type
http://www.securitytracker.com/id/1038170 No Types Assigned
http://www.securitytracker.com/id/1038170 Third Party Advisory, VDB Entry
Changed Reference Type
https://www.exploit-db.com/exploits/41779/ No Types Assigned
https://www.exploit-db.com/exploits/41779/ Exploit, Third Party Advisory, VDB Entry
Changed Reference Type
https://www.splunk.com/view/SP-CAAAPZ3#InformationLeakageviaJavaScriptCVE20175607 No Types Assigned
https://www.splunk.com/view/SP-CAAAPZ3#InformationLeakageviaJavaScriptCVE20175607 Vendor Advisory