Incorrect permission assignment for critical resource in Apache Hive - CVE-2024-29869
Published: June 26, 2025
Vulnerability details
The vulnerability allows a local user to gain access to potentially sensitive information.
The vulnerability exists due to hive creates a credentials file to a temporary directory in the file system with permissions 644 by default when the file permissions are not set explicitly. A local user with access to the directory can read the sensitive information written into this file.
Affected software
Netcool Operations Insight
watsonx.data
IBM Cloud Pak for Watson AIOps
How to mitigate CVE-2024-29869
Netcool Operations Insight - update to 1.6.15
watsonx.data - update to 2.2.1
IBM Cloud Pak for Watson AIOps - update to 4.10.0