Tuesday, April 29, 2025
HomeCVE/vulnerabilitySplunk Patched Critical Vulnerabilities in Enterprise Security

Splunk Patched Critical Vulnerabilities in Enterprise Security

Published on

SIEM as a Service

Follow Us on Google News

Several vulnerabilities have been discovered in Splunk Enterprise Security and Splunk User Behavior Analytics (UBA), which existed in several third-party packages.

The third-party package includes Splunk, which includes babel/traverse, handsontable, semver, loader-utils, json5, socket.io-parser, protobuf, and Guava.

However, Splunk has acted swiftly upon these vulnerabilities and patched them accordingly. The severity for these vulnerabilities ranges between 7.1 (High) and 9.8 (Critical).

- Advertisement - Google News
Document
Free Webinar

Fastrack Compliance: The Path to ZERO-Vulnerability

Compounding the problem are zero-day vulnerabilities like the MOVEit SQLi, Zimbra XSS, and 300+ such vulnerabilities that get discovered each month. Delays in fixing these vulnerabilities lead to compliance issues, these delay can be minimized with a unique feature on AppTrana that helps you to get “Zero vulnerability report” within 72 hours.

Technical Analysis

According to the reports shared with Cyber Security News, there were 13 vulnerabilities patched as per Splunk’s security advisories.

protobuf package had the highest number of vulnerabilities at 4 compared to other packages. 

The CVEs were CVE-2015-5237 (8.8), CVE-2022-3171 (7.5), CVE-2022-3509 (7.5), CVE-2022-3510 (7.5). With 3 vulnerabilities, loader-utils became the second package with the highest number of vulnerabilities with one critical vulnerability.

The CVEs of loader-utils package vulnerabilities were CVE-2022-37599 (7.5), CVE-2022-37603 (7.5), and CVE-2022-37601 (9.8).

Other third-party packages like babel/traverse, handsontable, semver, json5, socket.io-parser, and Guava had one high severity vulnerability each. The CVEs were as follows.

  • babel/traverse (CVE-2023-45133 – 8.8)
  • handsontable (CVE-2021-23446 – 7.5)
  • semver (CVE-2022-25883 – 7.5)
  • json5 (CVE-2022-46175 – 8.8)
  • socket.io-parser (CVE-2023-32695 – 7.5)
  • Guava (CVE-2023-2976 – 7.1)

Affected Products and Fixed in Version

ProductVersionComponentAffected VersionFix Version
Splunk Enterprise Security (ES)7.37.3.0
Splunk Enterprise Security (ES)7.27.2.0
Splunk Enterprise Security (ES)7.1Below 7.1.27.1.2
Splunk User Behavior Analytics (UBA)Below 5.3.05.3.0
Splunk User Behavior Analytics (UBA)Below 5.2.15.2.1

It is recommended for users of these products to upgrade to the mentioned versions or higher to prevent these vulnerabilities from getting exploited by threat actors.

Looking for cost-effective penetration testing services? Try Kelltron’s to assess and evaluate the security posture of digital systems – 

Eswar
Eswar
Eswar is a Cyber security content editor with a passion for creating captivating and informative content. With years of experience under his belt in Cyber Security, he is covering Cyber Security News, technology and other news.

Latest articles

RansomHub Ransomware Deploys Malware to Breach Corporate Networks

The eSentire’s Threat Response Unit (TRU) in early March 2025, a sophisticated cyberattack leveraging...

19 APT Hackers Target Asia-based Company Servers Using Exploited Vulnerabilities and Spear Phishing Email

The NSFOCUS Fuying Laboratory’s global threat hunting system identified 19 sophisticated Advanced Persistent Threat...

FBI Reports ₹1.38 Lakh Crore Loss in 2024, a 33% Surge from 2023

The FBI’s Internet Crime Complaint Center (IC3) has reported a record-breaking loss of $16.6...

Fog Ransomware Reveals Active Directory Exploitation Tools and Scripts

Cybersecurity researchers from The DFIR Report’s Threat Intel Group uncovered an open directory hosted...

Resilience at Scale

Why Application Security is Non-Negotiable

The resilience of your digital infrastructure directly impacts your ability to scale. And yet, application security remains a critical weak link for most organizations.

Application Security is no longer just a defensive play—it’s the cornerstone of cyber resilience and sustainable growth. In this webinar, Karthik Krishnamoorthy (CTO of Indusface) and Phani Deepak Akella (VP of Marketing – Indusface), will share how AI-powered application security can help organizations build resilience by

Discussion points


Protecting at internet scale using AI and behavioral-based DDoS & bot mitigation.
Autonomously discovering external assets and remediating vulnerabilities within 72 hours, enabling secure, confident scaling.
Ensuring 100% application availability through platforms architected for failure resilience.
Eliminating silos with real-time correlation between attack surface and active threats for rapid, accurate mitigation

More like this

RansomHub Ransomware Deploys Malware to Breach Corporate Networks

The eSentire’s Threat Response Unit (TRU) in early March 2025, a sophisticated cyberattack leveraging...

19 APT Hackers Target Asia-based Company Servers Using Exploited Vulnerabilities and Spear Phishing Email

The NSFOCUS Fuying Laboratory’s global threat hunting system identified 19 sophisticated Advanced Persistent Threat...

FBI Reports ₹1.38 Lakh Crore Loss in 2024, a 33% Surge from 2023

The FBI’s Internet Crime Complaint Center (IC3) has reported a record-breaking loss of $16.6...