Splunk through 7.0.1 is susceptible to information disclosure by appending __raw/services/server/info/server-info?output_mode=json to a query, as demonstrated by discovering a license key.
View the template here CVE-2018-11409.yaml
References:
https://www.exploit-db.com/exploits/44865/