First published: Mon Dec 21 2015(Updated: )
The LDAP implementation in HiveServer2 in Apache Hive before 1.0.1 and 1.1.x before 1.1.1, as used in IBM InfoSphere BigInsights 3.0, 3.0.0.1, and 3.0.0.2 and other products, mishandles simple unauthenticated and anonymous bind configurations, which allows remote attackers to bypass authentication via a crafted LDAP request.
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM InfoSphere BigInsights | =3.0.0.0 | |
IBM InfoSphere BigInsights | =3.0.0.1 | |
IBM InfoSphere BigInsights | =3.0.0.2 | |
Apache Hive | =1.0.0 | |
Apache Hive | =1.1.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2015-1772 is considered to have a medium severity due to its potential for unauthorized access.
To fix CVE-2015-1772, it is recommended to upgrade to Apache Hive version 1.0.1, 1.1.1, or later.
CVE-2015-1772 affects Apache Hive versions prior to 1.0.1 and 1.1.x before 1.1.1, as well as specific IBM InfoSphere BigInsights versions.
Yes, CVE-2015-1772 can be exploited remotely by attackers to bypass authentication.
CVE-2015-1772 impacts Apache Hive and specific versions of IBM InfoSphere BigInsights.