Denial of Service (DoS) in Splunk Enterprise Using a Malformed SAML Request
Vulnerability Description
In Splunk Enterprise versions lower than 9.0.6 and 8.2.12, a malicious actor can send a malformed security assertion markup language (SAML) request to the `/saml/acs` REST endpoint which can cause a denial of service through a crash or hang of the Splunk daemon.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2023-40593
Credits & Attribution
The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:
- Aaron Devaney (Dodekeract)
References
More from Splunk
View All →Affected Vendor
Splunk
View all reports →