Início
Início
Tendências
Tendências
Vulnerabilidades
Vulnerabilidades
Notícias
Notícias
Pesquisadores
Pesquisadores
Por que dbugs?
Por que dbugs?
Configurações

Thomas Rega

Pesquisador deCareerBuilder
#40324de 56,330
7.3CVSS total
Vulnerabilidades · 1
PT-2015-5437
7.3
2015-12-21
Ibm · Ibm Infosphere Biginsights · CVE-2015-1772
**Name of the Vulnerable Software and Affected Versions** Apache Hive versions prior to 1.0.1 Apache Hive versions 1.1.x prior to 1.1.1 IBM InfoSphere BigInsights versions 3.0, 3.0.0.1, and 3.0.0.2 **Description** The issue concerns the LDAP implementation in HiveServer2, which improperly handles simple unauthenticated and anonymous bind configurations. This allows remote attackers to bypass authentication by sending a crafted LDAP request. **Recommendations** For Apache Hive versions prior to 1.0.1, update to version 1.0.1 or later. For Apache Hive versions 1.1.x prior to 1.1.1, update to version 1.1.1 or later. For IBM InfoSphere BigInsights versions 3.0, 3.0.0.1, and 3.0.0.2, consider restricting access to the LDAP implementation until a patch or update is available.