CVE-2015-1889SQL Injection in IBM Infosphere Biginsights

CWE-89SQL Injection3 documents3 sources
Severity
6.5MEDIUMNVD
EPSS
0.2%
top 53.11%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedApr 22
Latest updateMay 17

Description

The Big SQL component in IBM InfoSphere BigInsights 3.0 through 3.0.0.2 allows remote authenticated users to bypass intended HDFS data-access restrictions via (1) a crafted CREATE HADOOP TABLE statement referencing the data of an arbitrary user or (2) an import of a certain Hive table definition with the HCAT_SYNC_OBJECTS procedure.

CVSS vector

AV:N/AC:L/C:P/I:P/A:PExploitability: 8.0 | Impact: 6.4

Affected Packages1 packages

NVDibm/infosphere_biginsights3.0.0.0, 3.0.0.1, 3.0.0.2+2

🔴Vulnerability Details

2
GHSA
GHSA-xr4q-6qfj-q54q: The Big SQL component in IBM InfoSphere BigInsights 32022-05-17
CVEList
CVE-2015-1889: The Big SQL component in IBM InfoSphere BigInsights 32015-04-22
CVE-2015-1889 — SQL Injection in IBM | cvebase