Unrated severityNVD Advisory· Published Jan 3, 2012· Updated Apr 29, 2026
CVE-2011-4643
CVE-2011-4643
Description
Multiple directory traversal vulnerabilities in Splunk 4.x before 4.2.5 allow remote authenticated users to read arbitrary files via a .. (dot dot) in a URI to (1) Splunk Web or (2) the Splunkd HTTP Server, aka SPL-45243.
Affected products
26cpe:2.3:a:splunk:splunk:4.0:*:*:*:*:*:*:*+ 25 more
- cpe:2.3:a:splunk:splunk:4.0:*:*:*:*:*:*:*
- cpe:2.3:a:splunk:splunk:4.0.1:*:*:*:*:*:*:*
- cpe:2.3:a:splunk:splunk:4.0.10:*:*:*:*:*:*:*
- cpe:2.3:a:splunk:splunk:4.0.11:*:*:*:*:*:*:*
- cpe:2.3:a:splunk:splunk:4.0.2:*:*:*:*:*:*:*
- cpe:2.3:a:splunk:splunk:4.0.3:*:*:*:*:*:*:*
- cpe:2.3:a:splunk:splunk:4.0.4:*:*:*:*:*:*:*
- cpe:2.3:a:splunk:splunk:4.0.5:*:*:*:*:*:*:*
- cpe:2.3:a:splunk:splunk:4.0.6:*:*:*:*:*:*:*
- cpe:2.3:a:splunk:splunk:4.0.7:*:*:*:*:*:*:*
- cpe:2.3:a:splunk:splunk:4.0.8:*:*:*:*:*:*:*
- cpe:2.3:a:splunk:splunk:4.0.9:*:*:*:*:*:*:*
- cpe:2.3:a:splunk:splunk:4.1:*:*:*:*:*:*:*
- cpe:2.3:a:splunk:splunk:4.1.1:*:*:*:*:*:*:*
- cpe:2.3:a:splunk:splunk:4.1.2:*:*:*:*:*:*:*
- cpe:2.3:a:splunk:splunk:4.1.3:*:*:*:*:*:*:*
- cpe:2.3:a:splunk:splunk:4.1.4:*:*:*:*:*:*:*
- cpe:2.3:a:splunk:splunk:4.1.5:*:*:*:*:*:*:*
- cpe:2.3:a:splunk:splunk:4.1.6:*:*:*:*:*:*:*
- cpe:2.3:a:splunk:splunk:4.1.7:*:*:*:*:*:*:*
- cpe:2.3:a:splunk:splunk:4.1.8:*:*:*:*:*:*:*
- cpe:2.3:a:splunk:splunk:4.2:*:*:*:*:*:*:*
- cpe:2.3:a:splunk:splunk:4.2.1:*:*:*:*:*:*:*
- cpe:2.3:a:splunk:splunk:4.2.2:*:*:*:*:*:*:*
- cpe:2.3:a:splunk:splunk:4.2.3:*:*:*:*:*:*:*
- cpe:2.3:a:splunk:splunk:4.2.4:*:*:*:*:*:*:*
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
7- www.exploit-db.com/exploits/18245/nvdExploit
- www.sec-1.com/blog/wp-content/uploads/2011/12/Attacking_Splunk_Release.pdfnvdExploit
- www.splunk.com/view/SP-CAAAGMMnvdVendor Advisory
- secunia.com/advisories/47232nvd
- www.sec-1.com/blog/nvd
- www.securitytracker.com/idnvd
- exchange.xforce.ibmcloud.com/vulnerabilities/72244nvd
News mentions
0No linked articles in our index yet.