CVE-2015-1836: High severity IBM Infosphere BigInsights vulnerability
Apache HBase 0.98 before 0.98.12.1, 1.0 before 1.0.1.1, and 1.1 before 1.1.0.1, as used in IBM InfoSphere BigInsights 3.0, 3.0.0.1, and 3.0.0.2 and other products, uses incorrect ACLs for ZooKeeper coordination state, which allows remote attackers to cause a denial of service (daemon outage), obtain sensitive information, or modify data via unspecified client traffic.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2015-1836?
CVE-2015-1836 has a medium severity rating due to its potential for causing denial of service.
How do I fix CVE-2015-1836?
To mitigate CVE-2015-1836, upgrade Apache HBase to version 0.98.12.1 or higher, 1.0.1.1 or higher, or 1.1.0.1 or higher.
What products are affected by CVE-2015-1836?
CVE-2015-1836 affects Apache HBase versions prior to 0.98.12.1, 1.0.1.1, and 1.1.0.1, as well as IBM InfoSphere BigInsights versions 3.0.0.0, 3.0.0.1, and 3.0.0.2.
What is the impact of CVE-2015-1836?
The impact of CVE-2015-1836 includes the possibility of denial of service that can lead to daemon outages.
Is CVE-2015-1836 related to authentication flaws?
CVE-2015-1836 is related to incorrect ACLs for ZooKeeper coordination state, which can be exploited by remote attackers.