ZeroHour

CVE-2016-2174

CVSS 3.0
7.2 high
EPSS
2%p78
Published
()
Modified
Description

SQL injection vulnerability in the policy admin tool in Apache Ranger before 0.5.3 allows remote authenticated administrators to execute arbitrary SQL commands via the eventTime parameter to service/plugins/policies/eventTime.

Vendors
apache
Products
ranger
Weakness
CWE-89
Vector
CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.