ZeroHour

CVE-2016-6807

CVSS 3.0
9.8 critical
EPSS
2%p83
Published
()
Modified
Description

Custom commands may be executed on Ambari Agent (2.4.x, before 2.4.2) hosts without authorization, leading to unauthorized access to operations that may affect the underlying system. Such operations are invoked by the Ambari Agent process on Ambari Agent hosts, as the user executing the Ambari Agent process.

Vendors
apache
Products
ambari
Weakness
CWE-284
Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.