Cloudera Manager 5.5 and previous versions allows remote malicious users to enumerate user sessions via a request to /api/v11/users/sessions.
cloudera manager