U.S. flag   An official website of the United States government
Dot gov

Official websites use .gov
A .gov website belongs to an official government organization in the United States.

Https

Secure .gov websites use HTTPS
A lock (Dot gov) or https:// means you've safely connected to the .gov website. Share sensitive information only on official, secure websites.

Vulnerability Change Records for CVE-2024-22165

Change History

New CVE Received from Splunk Inc. 1/09/2024 12:15:12 PM

Action Type Old Value New Value
Added Description

								
							
							
						
In Splunk Enterprise Security (ES) versions lower than 7.1.2, an attacker can create a malformed Investigation to perform a denial of service (DoS). The malformed investigation prevents the generation and rendering of the Investigations manager until it is deleted.<br>The vulnerability requires an authenticated session and access to create an Investigation. It only affects the availability of the Investigations manager, but without the manager, the Investigations functionality becomes unusable for most users.
Added CVSS V3.1

								
							
							
						
Splunk Inc. AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Added CWE

								
							
							
						
Splunk Inc. CWE-20
Added Reference

								
							
							
						
Splunk Inc. https://advisory.splunk.com/advisories/SVD-2024-0102 [No types assigned]