CVE-2015-6867: High severity hp vertica vulnerability
Published Nov 4, 2015
·Updated
The vertica-udx-zygote process in HP Vertica 7.1.1 UDx does not require authentication, which allows remote attackers to execute arbitrary commands via a crafted packet, aka ZDI-CAN-2914.
Affected Software
2 affected components
HP Vertica=7.1.1
OpenText Vertica=7.1.1
Event History
Nov 4, 2015
CVE Published
via MITRE·02:00 AM
Data Sourced
via MITRE·02:00 AM
Description
Data Sourced
via NVD·03:59 AM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2015-6867?
CVE-2015-6867 has a high severity rating due to the potential for remote code execution.
2
How do I fix CVE-2015-6867?
CVE-2015-6867 can be mitigated by applying the latest patches provided by HP for Vertica 7.1.1.
3
What versions of software are affected by CVE-2015-6867?
CVE-2015-6867 affects HP Vertica and OpenText Vertica version 7.1.1.
4
What kind of attacks can exploit CVE-2015-6867?
CVE-2015-6867 can be exploited by remote attackers to execute arbitrary commands on the vulnerable system.
5
Is authentication required to exploit CVE-2015-6867?
No, CVE-2015-6867 does not require authentication, making it more vulnerable to attacks.