Show filters
4 Total Results
Displaying 1-4 of 4
Sort by:
Attacker Value
Unknown
CVE-2016-6815
Disclosure Date: October 13, 2017 (last updated November 26, 2024)
In Apache Ranger before 0.6.2, users with "keyadmin" role should not be allowed to change password for users with "admin" role.
0
Attacker Value
Unknown
CVE-2016-5395
Disclosure Date: September 26, 2016 (last updated November 25, 2024)
Cross-site scripting (XSS) vulnerability in the create user functionality in the policy admin tool in Apache Ranger before 0.6.1 allows remote authenticated administrators to inject arbitrary web script or HTML via vectors related to policies.
0
Attacker Value
Unknown
CVE-2016-2174
Disclosure Date: June 13, 2016 (last updated November 25, 2024)
SQL injection vulnerability in the policy admin tool in Apache Ranger before 0.5.3 allows remote authenticated administrators to execute arbitrary SQL commands via the eventTime parameter to service/plugins/policies/eventTime.
0
Attacker Value
Unknown
CVE-2016-0735
Disclosure Date: April 11, 2016 (last updated November 25, 2024)
Apache Ranger 0.5.x before 0.5.2 allows remote authenticated users to bypass intended parent resource-level access restrictions by leveraging mishandling of a resource-level exclude policy.
0