cbcvebase.
CVE-2015-1836
published 2015-12-21

CVE-2015-1836: Apache HBase 0.98 before 0.98.12.1, 1.0 before 1.0.1.1, and 1.1 before 1.1.0.1, as used in IBM InfoSphere BigInsights 3.0, 3.0.0.1, and 3.0.0.2 and other…

PriorityP342high7.3CVSS 3.0
AVNACLPRNUINSUCLILAL
EPSS
7.42%
93.8th percentile
Apache HBase 0.98 before 0.98.12.1, 1.0 before 1.0.1.1, and 1.1 before 1.1.0.1, as used in IBM InfoSphere BigInsights 3.0, 3.0.0.1, and 3.0.0.2 and other products, uses incorrect ACLs for ZooKeeper coordination state, which allows remote attackers to cause a denial of service (daemon outage), obtain sensitive information, or modify data via unspecified client traffic.

Affected

18 ranges
VendorProductVersion rangeFixed in
apachehbase
apachehbase
apachehbase
apachehbase
apachehbase
apachehbase
apachehbase
apachehbase
apachehbase
apachehbase
apachehbase
apachehbase
apachehbase
apachehbase
apachehbase
ibminfosphere_biginsights
ibminfosphere_biginsights
ibminfosphere_biginsights

CVSS provenance

nvdv3.07.3HIGHCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
vendor_redhat7.3HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.