CVE-2016-5395
Status: ModifiedMedium (4.8)—
Cross-site scripting (XSS) vulnerability in the create user functionality in the policy admin tool in Apache Ranger before 0.6.1 allows remote authenticated administrators to inject arbitrary web script or HTML via vectors related to policies.
CVSS
- Version: 3.0
- Vector: CVSS:3.0/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N
- Base score: 4.8
Exploitation probability (EPSS)
- Probability of exploitation in the next 30 days: 2.10%
- Percentile among all scored CVEs: 81
- Score date: 10/6/2026
EPSS (Exploit Prediction Scoring System, FIRST) estimates how likely a vulnerability is to be exploited in the wild within 30 days. It complements CVSS (impact) and CISA KEV (confirmed exploitation).
Affected technologies (1)
CWEs
- CWE-79
References
Raw JSON (NVD)
Show
{
"id": "CVE-2016-5395",
"cveTags": [],
"metrics": {
"cvssMetricV2": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"version": "2.0",
"baseScore": 3.5,
"accessVector": "NETWORK",
"vectorString": "AV:N/AC:M/Au:S/C:N/I:P/A:N",
"authentication": "SINGLE",
"integrityImpact": "PARTIAL",
"accessComplexity": "MEDIUM",
"availabilityImpact": "NONE",
"confidentialityImpact": "NONE"
},
"acInsufInfo": false,
"impactScore": 2.9,
"baseSeverity": "LOW",
"obtainAllPrivilege": false,
"exploitabilityScore": 6.8,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": false,
"userInteractionRequired": true
}
],
"cvssMetricV30": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"scope": "CHANGED",
"version": "3.0",
"baseScore": 4.8,
"attackVector": "NETWORK",
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.0/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N",
"integrityImpact": "LOW",
"userInteraction": "REQUIRED",
"attackComplexity": "LOW",
"availabilityImpact": "NONE",
"privilegesRequired": "HIGH",
"confidentialityImpact": "LOW"
},
"impactScore": 2.7,
"exploitabilityScore": 1.7
}
]
},
"affected": [
{
"source": "secalert@redhat.com",
"affectedData": [
{
"vendor": "n/a",
"product": "n/a",
"versions": [
{
"status": "affected",
"version": "n/a"
}
]
}
]
}
],
"published": "2016-09-26T14:59:04.210",
"references": [
{
"url": "http://www.securityfocus.com/bid/92577",
"tags": [
"Third Party Advisory",
"VDB Entry"
],
"source": "secalert@redhat.com"
},
{
"url": "https://cwiki.apache.org/confluence/display/RANGER/Vulnerabilities+found+in+Ranger",
"tags": [
"Vendor Advisory"
],
"source": "secalert@redhat.com"
},
{
"url": "http://www.securityfocus.com/bid/92577",
"tags": [
"Third Party Advisory",
"VDB Entry"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://cwiki.apache.org/confluence/display/RANGER/Vulnerabilities+found+in+Ranger",
"tags": [
"Vendor Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
],
"vulnStatus": "Modified",
"weaknesses": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"description": [
{
"lang": "en",
"value": "CWE-79"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "Cross-site scripting (XSS) vulnerability in the create user functionality in the policy admin tool in Apache Ranger before 0.6.1 allows remote authenticated administrators to inject arbitrary web script or HTML via vectors related to policies."
},
{
"lang": "es",
"value": "Vulnerabilidad de XSS en la funcionalidad de crear usuario en la herramienta de administración de políticas en Apache Ranger en versiones anteriores a 0.6.1 permite a administradores remotos autenticados inyectar secuencias de comandos web o HTML arbitrarios a través de vectores relacionados con políticas."
}
],
"lastModified": "2026-06-17T00:49:19.977",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:apache:ranger:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "5D3EE296-72E0-4D7A-8A3D-EED6D30FB55B",
"versionEndIncluding": "0.5.0"
},
{
"criteria": "cpe:2.3:a:apache:ranger:0.5.1:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "D6909D4B-7BE3-4F29-8982-A5377D63BB17"
},
{
"criteria": "cpe:2.3:a:apache:ranger:0.5.2:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "0479F35C-191B-4C25-9133-19FD57CAC286"
},
{
"criteria": "cpe:2.3:a:apache:ranger:0.5.3:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "88754111-7402-4D9D-8EC5-41FE8247A671"
},
{
"criteria": "cpe:2.3:a:apache:ranger:0.6.0:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "90B9E6C0-9400-416B-9E31-309A9B988B6C"
}
],
"operator": "OR"
}
]
}
],
"sourceIdentifier": "secalert@redhat.com"
}