« Back to list

CVE-2016-6815

Status: ModifiedMedium (6.5)—

In Apache Ranger before 0.6.2, users with "keyadmin" role should not be allowed to change password for users with "admin" role.

CVSS

Exploitation probability (EPSS)

EPSS (Exploit Prediction Scoring System, FIRST) estimates how likely a vulnerability is to be exploited in the wild within 30 days. It complements CVSS (impact) and CISA KEV (confirmed exploitation).

Affected technologies (1)

CWEs

References

Raw JSON (NVD)

Show
{
  "id": "CVE-2016-6815",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 4,
          "accessVector": "NETWORK",
          "vectorString": "AV:N/AC:L/Au:S/C:N/I:P/A:N",
          "authentication": "SINGLE",
          "integrityImpact": "PARTIAL",
          "accessComplexity": "LOW",
          "availabilityImpact": "NONE",
          "confidentialityImpact": "NONE"
        },
        "acInsufInfo": false,
        "impactScore": 2.9,
        "baseSeverity": "MEDIUM",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 8,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": false
      }
    ],
    "cvssMetricV30": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.0",
          "baseScore": 6.5,
          "attackVector": "NETWORK",
          "baseSeverity": "MEDIUM",
          "vectorString": "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N",
          "integrityImpact": "HIGH",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "NONE",
          "privilegesRequired": "LOW",
          "confidentialityImpact": "NONE"
        },
        "impactScore": 3.6,
        "exploitabilityScore": 2.8
      }
    ]
  },
  "affected": [
    {
      "source": "security@apache.org",
      "affectedData": [
        {
          "vendor": "Apache Software Foundation",
          "product": "Apache Ranger",
          "versions": [
            {
              "status": "affected",
              "version": "0.5.x"
            },
            {
              "status": "affected",
              "version": "0.6.0"
            },
            {
              "status": "affected",
              "version": "0.6.1"
            }
          ]
        }
      ]
    }
  ],
  "published": "2017-10-13T14:29:00.207",
  "references": [
    {
      "url": "http://www.securityfocus.com/bid/94221",
      "tags": [
        "Third Party Advisory",
        "VDB Entry"
      ],
      "source": "security@apache.org"
    },
    {
      "url": "https://cwiki.apache.org/confluence/display/RANGER/Vulnerabilities+found+in+Ranger",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "security@apache.org"
    },
    {
      "url": "http://www.securityfocus.com/bid/94221",
      "tags": [
        "Third Party Advisory",
        "VDB Entry"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://cwiki.apache.org/confluence/display/RANGER/Vulnerabilities+found+in+Ranger",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-255"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "In Apache Ranger before 0.6.2, users with \"keyadmin\" role should not be allowed to change password for users with \"admin\" role."
    },
    {
      "lang": "es",
      "value": "En Apache Ranger en versiones anteriores a la 0.6.2, los usuarios con el rol \"keyadmin\" no deberían poder cambiar la contraseña de los usuarios con el rol \"admin\"."
    }
  ],
  "lastModified": "2026-06-17T00:51:49.510",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:apache:ranger:0.4.0:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "28DA5B21-3588-40F7-A9A8-6EB379D7102C"
            },
            {
              "criteria": "cpe:2.3:a:apache:ranger:0.5.0:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "A1FF8B11-2BF3-4845-AD13-87D960D73E5D"
            },
            {
              "criteria": "cpe:2.3:a:apache:ranger:0.5.1:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "D6909D4B-7BE3-4F29-8982-A5377D63BB17"
            },
            {
              "criteria": "cpe:2.3:a:apache:ranger:0.5.2:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "0479F35C-191B-4C25-9133-19FD57CAC286"
            },
            {
              "criteria": "cpe:2.3:a:apache:ranger:0.5.3:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "88754111-7402-4D9D-8EC5-41FE8247A671"
            },
            {
              "criteria": "cpe:2.3:a:apache:ranger:0.6.0:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "90B9E6C0-9400-416B-9E31-309A9B988B6C"
            },
            {
              "criteria": "cpe:2.3:a:apache:ranger:0.6.1:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "498B2C25-FB79-4B7C-A80B-B2EEDBE34C13"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "security@apache.org"
}