« Volver al listado

CVE-2015-3270

Estado: ModificadaMedia (6.5)—

Apache Ambari before 2.0.2 or 2.1.x before 2.1.1 allows remote authenticated users to gain administrative privileges via unspecified vectors, possibly related to changing passwords.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2015-3270",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 6.5,
          "accessVector": "NETWORK",
          "vectorString": "AV:N/AC:L/Au:S/C:P/I:P/A:P",
          "authentication": "SINGLE",
          "integrityImpact": "PARTIAL",
          "accessComplexity": "LOW",
          "availabilityImpact": "PARTIAL",
          "confidentialityImpact": "PARTIAL"
        },
        "acInsufInfo": false,
        "impactScore": 6.4,
        "baseSeverity": "MEDIUM",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 8,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": false
      }
    ]
  },
  "affected": [
    {
      "source": "secalert@redhat.com",
      "affectedData": [
        {
          "vendor": "n/a",
          "product": "n/a",
          "versions": [
            {
              "status": "affected",
              "version": "n/a"
            }
          ]
        }
      ]
    }
  ],
  "published": "2015-11-02T19:59:02.980",
  "references": [
    {
      "url": "http://www.openwall.com/lists/oss-security/2015/10/13/3",
      "source": "secalert@redhat.com"
    },
    {
      "url": "https://cwiki.apache.org/confluence/display/AMBARI/Ambari+Vulnerabilities",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "secalert@redhat.com"
    },
    {
      "url": "http://www.openwall.com/lists/oss-security/2015/10/13/3",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://cwiki.apache.org/confluence/display/AMBARI/Ambari+Vulnerabilities",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-264"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "Apache Ambari before 2.0.2 or 2.1.x before 2.1.1 allows remote authenticated users to gain administrative privileges via unspecified vectors, possibly related to changing passwords."
    },
    {
      "lang": "es",
      "value": "Apache Ambari en versiones anteriores a 2.0.2 o 2.1.x en versiones anteriores a 2.1.1 permite a usuarios remotos autenticados obtener privilegios administrativos a través de vectores no especificados, posiblemente relacionados con cambios de contraseñas."
    }
  ],
  "lastModified": "2026-06-17T00:25:38.740",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:apache:ambari:1.7.0:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "82B04633-452E-4D58-BA1F-4321D1330E60"
            },
            {
              "criteria": "cpe:2.3:a:apache:ambari:2.0.0:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "3394B0FD-5DD2-434B-8E83-429CE2B9E1DF"
            },
            {
              "criteria": "cpe:2.3:a:apache:ambari:2.0.1:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "96ECE226-03F0-4C10-972D-96EFE28A67EA"
            },
            {
              "criteria": "cpe:2.3:a:apache:ambari:2.1.0:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "3D5FA9F4-80F6-4990-A9DA-CC3820C66DB0"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "secalert@redhat.com"
}