Impact
In Splunk Enterprise versions prior to 10.4.3, a user holding the list_spl2_modules capability can inject SQL into the SPL2 module filtering process. This injection is possible because the system does not parameterize user‑supplied values before using them in database queries. The result is that an attacker can query the underlying data store through the REST API and read all relevant data, including private SPL2 module definitions that belong to other users, leading to a confidentiality breach. The underlying weakness aligns with CWE‑89, an unsanitized SQL query condition.
Affected Systems
Splunk, Splunk Enterprise is affected. Any release below 10.4.3, except those specifically noted as not affected (10.2.x, 10.0.x, and 9.4.x), is vulnerable. This means that versions such as 10.3.x and earlier 9.x releases fall into this risk window.
Risk and Exploitability
The CVSS score of 6.5 indicates moderate severity, and the EPSS score is not available, so the exact exploitation probability is unknown. The vulnerability is not listed in the CISA KEV catalog, suggesting no confirmed widespread exploitation as of now. The likely attack vector requires an authenticated user with the list_spl2_modules capability, which can be exercised via the SPL2 module filtering interface or REST API calls. While the risk is moderate, it offers direct read access to sensitive configuration data, warranting timely remediation.
OpenCVE Enrichment