Critical severity9.8NVD Advisory· Published Nov 30, 2017· Updated May 13, 2026
CVE-2017-17067
CVE-2017-17067
Description
Splunk Web in Splunk Enterprise 7.0.x before 7.0.0.1, 6.6.x before 6.6.3.2, 6.5.x before 6.5.6, 6.4.x before 6.4.9, and 6.3.x before 6.3.12, when the SAML authType is enabled, mishandles SAML, which allows remote attackers to bypass intended access restrictions or conduct impersonation attacks.
Affected products
1Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
2- www.securityfocus.com/bid/102005nvdThird Party AdvisoryVDB Entry
- www.splunk.com/view/SP-CAAAP3KnvdVendor Advisory
News mentions
0No linked articles in our index yet.