Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2015-1772

Опубликовано: 21 дек. 2015
Источник: nvd
CVSS3: 7.3
CVSS2: 4.3
EPSS Низкий

Описание

The LDAP implementation in HiveServer2 in Apache Hive before 1.0.1 and 1.1.x before 1.1.1, as used in IBM InfoSphere BigInsights 3.0, 3.0.0.1, and 3.0.0.2 and other products, mishandles simple unauthenticated and anonymous bind configurations, which allows remote attackers to bypass authentication via a crafted LDAP request.

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:ibm:infosphere_biginsights:3.0.0.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:infosphere_biginsights:3.0.0.1:*:*:*:*:*:*:*
cpe:2.3:a:ibm:infosphere_biginsights:3.0.0.2:*:*:*:*:*:*:*
Конфигурация 2

Одно из

cpe:2.3:a:apache:hive:1.0.0:*:*:*:*:*:*:*
cpe:2.3:a:apache:hive:1.1.0:*:*:*:*:*:*:*

EPSS

Процентиль: 38%
0.00163
Низкий

7.3 High

CVSS3

4.3 Medium

CVSS2

Дефекты

CWE-287

Связанные уязвимости

redhat
больше 10 лет назад

The LDAP implementation in HiveServer2 in Apache Hive before 1.0.1 and 1.1.x before 1.1.1, as used in IBM InfoSphere BigInsights 3.0, 3.0.0.1, and 3.0.0.2 and other products, mishandles simple unauthenticated and anonymous bind configurations, which allows remote attackers to bypass authentication via a crafted LDAP request.

CVSS3: 7.3
github
почти 7 лет назад

Improper Authentication in org.apache.hive:hive, org.apache.hive:hive-exec, and org.apache.hive:hive-service

EPSS

Процентиль: 38%
0.00163
Низкий

7.3 High

CVSS3

4.3 Medium

CVSS2

Дефекты

CWE-287