Show filters
22 Total Results
Displaying 1-10 of 22
Sort by:
Attacker Value
Unknown

CVE-2021-30132

Disclosure Date: November 08, 2021 (last updated February 23, 2025)
Cloudera Manager 7.2.4 has Incorrect Access Control, allowing Escalation of Privileges.
Attacker Value
Unknown

CVE-2021-32483

Disclosure Date: November 08, 2021 (last updated February 23, 2025)
Cloudera Manager 7.2.4 has Incorrect Access Control, allowing Escalation of Privileges to view the restricted Dashboard.
Attacker Value
Unknown

CVE-2021-29243

Disclosure Date: November 08, 2021 (last updated February 23, 2025)
Cloudera Manager 5.x, 6.x, 7.1.x, 7.2.x, and 7.3.x allows XSS.
Attacker Value
Unknown

CVE-2021-32482

Disclosure Date: November 08, 2021 (last updated February 23, 2025)
Cloudera Manager 5.x, 6.x, 7.1.x, 7.2.x, and 7.3.x allows XSS via the path parameter.
Attacker Value
Unknown

CVE-2019-14449

Disclosure Date: November 26, 2019 (last updated November 27, 2024)
An issue was discovered in Cloudera Manager 5.x before 5.16.2, 6.0.x before 6.0.2, and 6.1.x before 6.1.1. Malicious impala queries can result in Cross Site Scripting (XSS) when viewed within this product.
Attacker Value
Unknown

CVE-2017-7399

Disclosure Date: November 26, 2019 (last updated November 27, 2024)
Cloudera Manager 5.8.x before 5.8.5, 5.9.x before 5.9.2, and 5.10.x before 5.10.1 allows a read-only Cloudera Manager user to discover the usernames of other users and elevate the privileges of those users.
Attacker Value
Unknown

CVE-2016-9271

Disclosure Date: November 26, 2019 (last updated November 27, 2024)
Cloudera Manager 5.7.x before 5.7.6, 5.8.x before 5.8.4, and 5.9.x before 5.9.1 allows XSS in the help search feature.
Attacker Value
Unknown

CVE-2015-4457

Disclosure Date: November 26, 2019 (last updated November 27, 2024)
Multiple cross-site scripting (XSS) vulnerabilities in the Cloudera Manager UI before 5.4.3 allow remote authenticated users to inject arbitrary web script or HTML using unspecified vectors.
Attacker Value
Unknown

CVE-2015-6495

Disclosure Date: November 26, 2019 (last updated November 27, 2024)
There is Sensitive Information in Cloudera Manager before 5.4.6 Diagnostic Support Bundles.
Attacker Value
Unknown

CVE-2016-3192

Disclosure Date: November 26, 2019 (last updated November 27, 2024)
Cloudera Manager 5.x before 5.7.1 places Sensitive Data in cleartext Readable Files.