CVE-2015-1836 Information
Description
Apache HBase 0.98 before 0.98.12.1 1.0 before 1.0.1.1 and 1.1 before 1.1.0.1 as used in IBM InfoSphere BigInsights 3.0 3.0.0.1 and 3.0.0.2 and other products uses incorrect ACLs for ZooKeeper coordination state which allows remote attackers to cause a denial of service (daemon outage) obtain sensitive information or modify data via unspecified client traffic.
CVSS Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
Reference
http://mail-archives.apache.org/mod_mbox/www-announce/201505.mbox/3CCA+RK=_CFiTfQ2d0V+kuJx_y5izmYccaKjXaJ3V72KK7tbOhbkg@mail.gmail.com3E http://www.securitytracker.com/id/1034365 http://www-01.ibm.com/support/docview.wss?uid=swg21969546 https://www.cloudera.com/documentation/other/security-bulletins/topics/csb_topic_1.html
Attack Complexity
LOW
Privileges Required
NONE
User Interaction Required
NONE
Scope
NONE
Confidentiality Impact
UNCHANGED
Integrity Impact
LOW
Availability Impact
LOW
Base Score
LOW
Base Severity
7.3
Share on: