Impact
The vulnerability is a SQL injection flaw, identified as CWE-74, that occurs when Splunk SOAR builds a database lookup using a supplied list name without parameter binding. This flaw allows a user with the Automation Engineer role to execute arbitrary Structured Query Language statements against the Splunk SOAR database. The attacker can perform create, read, update and delete operations on all data stored in the database.
Affected Systems
Splunk SOAR versions prior to 8.6.0 are affected. The advisory specifically mentions that any instance running these versions is vulnerable when an Automation Engineer role is assigned to a user.
Risk and Exploitability
The vulnerability has a CVSS score of 6.5, indicating a moderate impact. No EPSS score is available, and the issue is not listed in the CISA KEV catalog. Attackers would need to be authenticated with an Automation Engineer role inside the application to exploit this flaw. Once exploited, the attacker could alter, delete, or exfiltrate any data stored in the Splunk SOAR database. Based on the description, it is inferred that the attack vector requires authenticated access within Splunk SOAR rather than remote exploitation from outside the network.
OpenCVE Enrichment