Information disclosure in Hadoop - CVE-2017-15713

 

Information disclosure in Hadoop - CVE-2017-15713

Published: January 19, 2018 / Updated: August 8, 2020


Vulnerability identifier: #VU37620
CSH Severity: Medium
CVSS v4: 7.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2017-15713
CWE-ID: CWE-200
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote authenticated user to gain access to sensitive information.

Vulnerability in Apache Hadoop 0.23.x, 2.x before 2.7.5, 2.8.x before 2.8.3, and 3.0.0-alpha through 3.0.0-beta1 allows a cluster user to expose private files owned by the user running the MapReduce job history server process. The malicious user can construct a configuration file containing XML directives that reference sensitive files on the MapReduce job history server host.


Affected software

Hadoop
IBM Cloud Pak for Multicloud Management Monitoring
IBM Cloud Application Performance Management (APM)
IBM Qradar SIEM
Fedora
watsonx.data
hadoop
IBM InfoSphere Information Server

How to mitigate CVE-2017-15713

Install update from vendor's website.

IBM Cloud Pak for Multicloud Management Monitoring - update to 2.3 Fix Pack 5
IBM Qradar SIEM - addressed in versions 7.3.3 Fix Pack 10, 7.4.3 Fix Pack 3, 7.4.3 Fix Pack 4
watsonx.data - update to 2.0.2
hadoop - addressed in versions 2.7.6-2.fc28, 2.7.6-4.fc28
IBM Cloud Application Performance Management (APM) - update to 8.1.4.0.16
IBM InfoSphere Information Server - update to 11.7.1.4 Service pack 1

External References

Related Security Bulletins