CVE-2016-2174: SQL Injection
Published Jun 13, 2016
·Updated
SQL injection vulnerability in the policy admin tool in Apache Ranger before 0.5.3 allows remote authenticated administrators to execute arbitrary SQL commands via the eventTime parameter to service/plugins/policies/eventTime.
Affected Software
3 affected components
Apache Ranger=0.5.0
Apache Ranger=0.5.1
Apache Ranger=0.5.2
Event History
Jun 13, 2016
CVE Published
via MITRE·02:00 PM
Data Sourced
via MITRE·02:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2016-2174?
CVE-2016-2174 is considered a high severity vulnerability due to its potential for remote authenticated SQL injection attacks.
2
How do I fix CVE-2016-2174?
To fix CVE-2016-2174, upgrade Apache Ranger to version 0.5.3 or later.
3
Who is affected by CVE-2016-2174?
CVE-2016-2174 affects users of Apache Ranger versions 0.5.0 through 0.5.2.
4
What type of vulnerability is CVE-2016-2174?
CVE-2016-2174 is a SQL injection vulnerability that allows execution of arbitrary SQL commands.
5
Can CVE-2016-2174 be exploited remotely?
Yes, CVE-2016-2174 can be potentially exploited by remote authenticated administrators.