CVE-2014-5197
Directory traversal vulnerability in (1) Splunk Web or the (2) Splunkd HTTP Server in Splunk Enterprise 6.1.x before 6.1.3 allows remote authenticated users to read arbitrary files via a .. (dot dot) in a URI, related to search ids.
View on NVDSeverity
N/A
EPSS
Probability of exploitation (next 30 days): 0.0046 (0.5%)
Percentile: 64.4%
EPSS: 2026-05-06
Affects
splunk:splunkTechnical description
Directory traversal vulnerability in (1) Splunk Web or the (2) Splunkd HTTP Server in Splunk Enterprise 6.1.x before 6.1.3 allows remote authenticated users to read arbitrary files via a .. (dot dot) in a URI, related to search ids.
Published: 8/12/2014, 8:55:03 PM
Last modified: 5/6/2026, 10:30:45 PM