7.3
CVSSv3

CVE-2015-1772

Published: 21/12/2015 Updated: 07/11/2023
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
CVSS v3 Base Score: 7.3 | Impact Score: 3.4 | Exploitability Score: 3.9
VMScore: 383
Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N

Vulnerability Summary

The LDAP implementation in HiveServer2 in Apache Hive prior to 1.0.1 and 1.1.x prior to 1.1.1, as used in IBM InfoSphere BigInsights 3.0, 3.0.0.1, and 3.0.0.2 and other products, mishandles simple unauthenticated and anonymous bind configurations, which allows remote malicious users to bypass authentication via a crafted LDAP request.

Vulnerable Product Search on Vulmon Subscribe to Product

ibm infosphere biginsights 3.0.0.2

ibm infosphere biginsights 3.0.0.0

ibm infosphere biginsights 3.0.0.1

apache hive 1.1.0

apache hive 1.0.0