5.5
CVSSv2

CVE-2015-1775

Published: 02/11/2015 Updated: 04/11/2015
CVSS v2 Base Score: 5.5 | Impact Score: 4.9 | Exploitability Score: 8
VMScore: 490
Vector: AV:N/AC:L/Au:S/C:P/I:P/A:N

Vulnerability Summary

Server-side request forgery (SSRF) vulnerability in the proxy endpoint (api/v1/proxy) in Apache Ambari prior to 2.1.0 allows remote authenticated users to conduct port scans and access unsecured services via a crafted REST call.

Vulnerable Product Search on Vulmon Subscribe to Product

apache ambari 1.7.0

apache ambari 1.6.0

apache ambari 1.5.0

apache ambari 2.0.2

apache ambari 2.0.1

apache ambari 2.0.0

apache ambari 1.6.1

apache ambari 1.5.1