CVE-2015-1772: High severity IBM Infosphere BigInsights vulnerability
The LDAP implementation in HiveServer2 in Apache Hive before 1.0.1 and 1.1.x before 1.1.1, as used in IBM InfoSphere BigInsights 3.0, 3.0.0.1, and 3.0.0.2 and other products, mishandles simple unauthenticated and anonymous bind configurations, which allows remote attackers to bypass authentication via a crafted LDAP request.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2015-1772?
CVE-2015-1772 is considered to have a medium severity due to its potential for unauthorized access.
How do I fix CVE-2015-1772?
To fix CVE-2015-1772, it is recommended to upgrade to Apache Hive version 1.0.1, 1.1.1, or later.
What are the affected versions for CVE-2015-1772?
CVE-2015-1772 affects Apache Hive versions prior to 1.0.1 and 1.1.x before 1.1.1, as well as specific IBM InfoSphere BigInsights versions.
Can CVE-2015-1772 be exploited remotely?
Yes, CVE-2015-1772 can be exploited remotely by attackers to bypass authentication.
What products are affected by CVE-2015-1772?
CVE-2015-1772 impacts Apache Hive and specific versions of IBM InfoSphere BigInsights.