In Splunk Enterprise versions lower than 8.2.12, 9.0.6, and 9.1.1, an attacker can exploit an absolute path traversal to execute arbitrary code that is located on a separate disk.
https://research.splunk.com/application/356bd3fe-f59b-4f64-baa1-51495411b7ad/