9.8
CVSSv3

CVE-2016-3086

Published: 05/09/2017 Updated: 11/09/2017
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
CVSS v3 Base Score: 9.8 | Impact Score: 5.9 | Exploitability Score: 3.9
VMScore: 445
Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N

Vulnerability Summary

The YARN NodeManager in Apache Hadoop 2.6.x prior to 2.6.5 and 2.7.x prior to 2.7.3 can leak the password for credential store provider used by the NodeManager to YARN Applications.

Vulnerable Product Search on Vulmon Subscribe to Product

apache hadoop 2.6.2

apache hadoop 2.6.4

apache hadoop 2.7.0

apache hadoop 2.7.1

apache hadoop 2.7.2

apache hadoop 2.6.0

apache hadoop 2.6.1

apache hadoop 2.6.3