CVE-2016-2174

HIGH

Apache Ranger < 0.5.3 - Authenticated SQL Injection via eventTime Parameter

Title source: llm
STIX 2.1

Description

SQL injection vulnerability in the policy admin tool in Apache Ranger before 0.5.3 allows remote authenticated administrators to execute arbitrary SQL commands via the eventTime parameter to service/plugins/policies/eventTime.

References (2)

Core 2
Core References
Mailing List mailing-list x_refsource_mlist
http://www.openwall.com/lists/oss-security/2016/06/01/3

Scores

CVSS v3 7.2
EPSS 0.0058
EPSS Percentile 69.0%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-89
Status published
Products (4)
apache/ranger 0.5.0
apache/ranger 0.5.1
apache/ranger 0.5.2
org.apache.ranger/ranger 0 - 0.5.3Maven
Published Jun 13, 2016
Tracked Since Feb 18, 2026