How we can resolve this RCE in Splunk Enterprise through Insecure XML Parsing issue



We have been informed about a high-severity vulnerability (CVE-2023-46214) impacting Splunk Enterprise (RCE in Splunk Enterprise through Insecure XML Parsing)  as we are on Splunk Cloud Version:9.0.2303.201.


Labels (1)
0 Karma


Hi @AL3Z ..

Please check this Splunk Advisory:

the Splunk Cloud affected version is - Versions below 9.1.2308

The Splunk Cloud fix version is --------- 9.1.2308


So you should ask the Splunk Cloud Support and ask them to upgrade your Splunk Cloud to the fix version 9.1.2308, thanks. 

0 Karma


@inventsekar ,

They  recommended upgrading or updating the web.conf file in on-prem environment.
How we can do this  as its not the cloud its an enterprise.

0 Karma
Get Updates on the Splunk Community!

Detecting Remote Code Executions With the Splunk Threat Research Team

WATCH NOWRemote code execution (RCE) vulnerabilities pose a significant risk to organizations. If exploited, ...

Enter the Splunk Community Dashboard Challenge for Your Chance to Win!

The Splunk Community Dashboard Challenge is underway! This is your chance to showcase your skills in creating ...

.conf24 | Session Scheduler is Live!!

.conf24 is happening June 11 - 14 in Las Vegas, and we are thrilled to announce that the conference catalog ...