« Volver al listado

CVE-2016-6815

Estado: ModificadaMedia (6.5)—

In Apache Ranger before 0.6.2, users with "keyadmin" role should not be allowed to change password for users with "admin" role.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2016-6815",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 4,
          "accessVector": "NETWORK",
          "vectorString": "AV:N/AC:L/Au:S/C:N/I:P/A:N",
          "authentication": "SINGLE",
          "integrityImpact": "PARTIAL",
          "accessComplexity": "LOW",
          "availabilityImpact": "NONE",
          "confidentialityImpact": "NONE"
        },
        "acInsufInfo": false,
        "impactScore": 2.9,
        "baseSeverity": "MEDIUM",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 8,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": false
      }
    ],
    "cvssMetricV30": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.0",
          "baseScore": 6.5,
          "attackVector": "NETWORK",
          "baseSeverity": "MEDIUM",
          "vectorString": "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N",
          "integrityImpact": "HIGH",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "NONE",
          "privilegesRequired": "LOW",
          "confidentialityImpact": "NONE"
        },
        "impactScore": 3.6,
        "exploitabilityScore": 2.8
      }
    ]
  },
  "affected": [
    {
      "source": "security@apache.org",
      "affectedData": [
        {
          "vendor": "Apache Software Foundation",
          "product": "Apache Ranger",
          "versions": [
            {
              "status": "affected",
              "version": "0.5.x"
            },
            {
              "status": "affected",
              "version": "0.6.0"
            },
            {
              "status": "affected",
              "version": "0.6.1"
            }
          ]
        }
      ]
    }
  ],
  "published": "2017-10-13T14:29:00.207",
  "references": [
    {
      "url": "http://www.securityfocus.com/bid/94221",
      "tags": [
        "Third Party Advisory",
        "VDB Entry"
      ],
      "source": "security@apache.org"
    },
    {
      "url": "https://cwiki.apache.org/confluence/display/RANGER/Vulnerabilities+found+in+Ranger",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "security@apache.org"
    },
    {
      "url": "http://www.securityfocus.com/bid/94221",
      "tags": [
        "Third Party Advisory",
        "VDB Entry"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://cwiki.apache.org/confluence/display/RANGER/Vulnerabilities+found+in+Ranger",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-255"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "In Apache Ranger before 0.6.2, users with \"keyadmin\" role should not be allowed to change password for users with \"admin\" role."
    },
    {
      "lang": "es",
      "value": "En Apache Ranger en versiones anteriores a la 0.6.2, los usuarios con el rol \"keyadmin\" no deberían poder cambiar la contraseña de los usuarios con el rol \"admin\"."
    }
  ],
  "lastModified": "2026-06-17T00:51:49.510",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:apache:ranger:0.4.0:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "28DA5B21-3588-40F7-A9A8-6EB379D7102C"
            },
            {
              "criteria": "cpe:2.3:a:apache:ranger:0.5.0:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "A1FF8B11-2BF3-4845-AD13-87D960D73E5D"
            },
            {
              "criteria": "cpe:2.3:a:apache:ranger:0.5.1:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "D6909D4B-7BE3-4F29-8982-A5377D63BB17"
            },
            {
              "criteria": "cpe:2.3:a:apache:ranger:0.5.2:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "0479F35C-191B-4C25-9133-19FD57CAC286"
            },
            {
              "criteria": "cpe:2.3:a:apache:ranger:0.5.3:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "88754111-7402-4D9D-8EC5-41FE8247A671"
            },
            {
              "criteria": "cpe:2.3:a:apache:ranger:0.6.0:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "90B9E6C0-9400-416B-9E31-309A9B988B6C"
            },
            {
              "criteria": "cpe:2.3:a:apache:ranger:0.6.1:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "498B2C25-FB79-4B7C-A80B-B2EEDBE34C13"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "security@apache.org"
}