CVE-2015-4940: Infoleak
Apache Ambari before 2.1, as used in IBM Infosphere BigInsights 4.x before 4.1, stores a cleartext BigSheets password in a configuration file, which allows local users to obtain sensitive information by reading this file.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2015-4940?
CVE-2015-4940 is classified as a medium severity vulnerability due to the risk associated with exposing sensitive information.
How do I fix CVE-2015-4940?
To fix CVE-2015-4940, upgrade Apache Ambari to version 2.1 or later, which addresses the insecure storage of passwords.
What are the potential impacts of CVE-2015-4940?
The potential impacts of CVE-2015-4940 include unauthorized access to sensitive BigSheets passwords by local users.
Which versions of Apache Ambari are affected by CVE-2015-4940?
Apache Ambari versions prior to 2.1 are affected by CVE-2015-4940.
Does CVE-2015-4940 affect IBM InfoSphere BigInsights?
Yes, CVE-2015-4940 affects IBM InfoSphere BigInsights 4.x versions before 4.1, specifically prior to version 4.1.