CVE-2015-1772
The LDAP implementation in HiveServer2 in Apache Hive before 1.0.1 and 1.1.x before 1.1.1, as used in IBM InfoSphere BigInsights 3.0, 3.0.0.1, and 3.0.0.2 and other products, mishandles simple unauthenticated and anonymous bind configurations, which…
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (6.83%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
The LDAP implementation in HiveServer2 in Apache Hive before 1.0.1 and 1.1.x before 1.1.1, as used in IBM InfoSphere BigInsights 3.0, 3.0.0.1, and 3.0.0.2 and other products, mishandles simple unauthenticated and anonymous bind configurations, which allows remote attackers to bypass authentication via a crafted LDAP request.
- CVSS 3.0
- 7.3 HIGHCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
- EPSS
- 6.83% probability · 94th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-287
- Affected
- ibm/infosphere biginsights · apache/hive
- Source
- secalert@redhat.com
References
- http://mail-archives.apache.org/mod_mbox/www-announce/201505.mbox/%3CCAOpgucy52yzNN1FaRcxwhZmx8ZtNRjmK6V0Bxk4svAD-R1q70Q%40mail.gmail.com%3E
- http://www-01.ibm.com/support/docview.wss?uid=swg21969546Vendor Advisory
- http://www.securitytracker.com/id/1034365
- https://www.cloudera.com/documentation/other/security-bulletins/topics/csb_topic_1.html
- http://mail-archives.apache.org/mod_mbox/www-announce/201505.mbox/%3CCAOpgucy52yzNN1FaRcxwhZmx8ZtNRjmK6V0Bxk4svAD-R1q70Q%40mail.gmail.com%3E
- http://www-01.ibm.com/support/docview.wss?uid=swg21969546Vendor Advisory
- http://www.securitytracker.com/id/1034365
- https://www.cloudera.com/documentation/other/security-bulletins/topics/csb_topic_1.html
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.