216.73.217.172

CVE-2025-22621

· Published 07/01/2025 17:15 · Modified 15/01/2025 17:15

Labels: CVE-2025-22621 2025-01-07CVE-2025-22621CWE-269[email protected]

Essential information

Published
07/01/2025 17:15
Modified
15/01/2025 17:15
Author
Creator
CVSS
6.4 MEDIUM (v3.1)
CISA KEV
No
CWE
CVSS vector
CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:N

CVSS metrics

Description

In versions 1.0.67 and lower of the Splunk App for SOAR, the Splunk documentation for that app recommended adding the `admin_all_objects` capability to the `splunk_app_soar` role. This addition could lead to improper access control for a low-privileged user that does not hold the "admin" Splunk roles.

NVD status

Status
Awaiting Analysis — CVE has been marked for Analysis. Normally once in this state the CVE will be analyzed by NVD staff within 24 hours.
Source
[email protected]
NVD
View on NVD

References