CVE-2024-36984

HIGH

Splunk < 9.0.10 - Insecure Deserialization

Title source: rule

Description

In Splunk Enterprise versions below 9.2.2, 9.1.5, and 9.0.10 on Windows, an authenticated user could execute a specially crafted query that they could then use to serialize untrusted data. The attacker could use the query to execute arbitrary code.

Scores

CVSS v3 8.8
EPSS 0.0346
EPSS Percentile 87.4%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Classification

CWE
CWE-502
Status published

Affected Products (1)

splunk/splunk < 9.0.10

Timeline

Published Jul 01, 2024
Tracked Since Feb 18, 2026