HTTP: Splunk Enterprise Data Model And Radio.html Stored Cross-Site Scripting

This signature detects attempts to exploit a known cross-site scripting vulnerability against Splunk Enterprise Data Model. It is due to insufficient validation of user-supplied input. Attackers can steal cookie-based authentication credentials and launch other attacks.

Extended Description

In Splunk Enterprise versions below 8.1.12, 8.2.9, and 9.0.2, an authenticated user can inject and store arbitrary scripts that can lead to persistent cross-site scripting (XSS) in the object name of a Data Model.

Affected Products

Splunk splunk_cloud_platform

Short Name
HTTP:XSS:SPLUNK-ENT-DATA-XSS
Severity
Major
Recommended
False
Recommended Action
Drop
Category
HTTP
Keywords
And CVE-2022-43568 CVE-2022-43569 Cross-Site Data Enterprise Model Radio.html Scripting Splunk Stored
Release Date
12/01/2022
Supported Platforms

srx-branch-12.3

srx-19.3

srx-branch-19.3

vsrx3bsd-19.2

srx-branch-19.4

vsrx-19.4

mx-12.3

mx-19.4

vmx-19.4

mx-19.3

vsrx3bsd-19.4

srx-19.4

vsrx-12.3

vmx-19.3

vsrx-19.2

srx-12.3

Sigpack Version
3857
False Positive
Unknown
Vendors

Splunk

Found a potential security threat?