3.5
CVSSv2

CVE-2015-3186

Published: 02/11/2015 Updated: 04/11/2015
CVSS v2 Base Score: 3.5 | Impact Score: 2.9 | Exploitability Score: 6.8
VMScore: 312
Vector: AV:N/AC:M/Au:S/C:N/I:P/A:N

Vulnerability Summary

Cross-site scripting (XSS) vulnerability in Apache Ambari prior to 2.1.0 allows remote authenticated cluster operator users to inject arbitrary web script or HTML via the note field in a configuration change.

Vulnerable Product Search on Vulmon Subscribe to Product

apache ambari

apache ambari 1.7.0

apache ambari 2.0.0

apache ambari 2.0.1