---
cve: "CVE-2011-4644"
severity: "LOW"
cvss: 3.1
epss: "7.5%"
vendor: "n/a"
kev: false
exploited: false
published: "2012-01-03 11:55:04"
tags: [cve, security, low]
source: tsecurity.de CVE-Dossier
exported: "2026-09-11T14:02:22+02:00"
---

# CVE-2011-4644

> 3.1 LOW · 🧪 PoC

## Beschreibung

Splunk 4.2.5 and earlier, when a Free license is selected, enables potentially undesirable functionality within an environment that intentionally does not support authentication, which allows remote attackers to (1) read arbitrary files via a management-console session that leverages the ability to create crafted data sources, or (2) execute management commands via an HTTP request.

## Exploit-Evidenz

- [EDB-18245 — Splunk - Remote Command Execution](https://www.exploit-db.com/exploits/18245) ✅

## Referenzen

- <http://www.sec-1.com/blog/?p=233>
- <http://www.sec-1.com/blog/wp-content/uploads/2011/12/Attacking_Splunk_Release.pdf>
- <http://www.exploit-db.com/exploits/18245/>

---
_Exportiert aus dem [tsecurity.de CVE-Dossier](https://tsecurity.de/cve?cve=CVE-2011-4644) · Datenquellen: EUVD (ENISA), NVD, OSV, CISA KEV, FIRST EPSS, Exploit-DB, BSI BITS_
