CVE-2015-1772 Information
Feb 14, 2021
cve
Description
The LDAP implementation in HiveServer2 in Apache Hive before 1.0.1 and 1.1.x before 1.1.1 as used in IBM InfoSphere BigInsights 3.0 3.0.0.1 and 3.0.0.2 and other products mishandles simple unauthenticated and anonymous bind configurations which allows remote attackers to bypass authentication via a crafted LDAP request.
CVSS Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
Reference
http://mail-archives.apache.org/mod_mbox/www-announce/201505.mbox/3CCAOpgucy52yzNN1FaRcxwhZmx8ZtNRjmK6V0Bxk4svAD-R1q70Q@mail.gmail.com3E http://www.securitytracker.com/id/1034365 http://www-01.ibm.com/support/docview.wss?uid=swg21969546 https://www.cloudera.com/documentation/other/security-bulletins/topics/csb_topic_1.html
Attack Complexity
LOW
Privileges Required
NONE
User Interaction Required
NONE
Scope
NONE
Confidentiality Impact
UNCHANGED
Integrity Impact
LOW
Availability Impact
LOW
Base Score
LOW
Base Severity
7.3
Share on: