Information disclosure in Hadoop - CVE-2017-15713
Published: January 19, 2018 / Updated: August 8, 2020
Vulnerability details
The vulnerability allows a remote authenticated user to gain access to sensitive information.
Vulnerability in Apache Hadoop 0.23.x, 2.x before 2.7.5, 2.8.x before 2.8.3, and 3.0.0-alpha through 3.0.0-beta1 allows a cluster user to expose private files owned by the user running the MapReduce job history server process. The malicious user can construct a configuration file containing XML directives that reference sensitive files on the MapReduce job history server host.
Affected software
IBM Cloud Pak for Multicloud Management Monitoring
IBM Cloud Application Performance Management (APM)
IBM Qradar SIEM
Fedora
watsonx.data
hadoop
IBM InfoSphere Information Server
How to mitigate CVE-2017-15713
IBM Qradar SIEM - addressed in versions 7.3.3 Fix Pack 10, 7.4.3 Fix Pack 3, 7.4.3 Fix Pack 4
watsonx.data - update to 2.0.2
hadoop - addressed in versions 2.7.6-2.fc28, 2.7.6-4.fc28
IBM Cloud Application Performance Management (APM) - update to 8.1.4.0.16
IBM InfoSphere Information Server - update to 11.7.1.4 Service pack 1
External References
Related Security Bulletins
- Multiple vulnerabilities in Hadoop
- Multiple vulnerabilities in IBM QRadar SIEM
- Multiple vulnerabilities in IBM QRadar SIEM
- Multiple vulnerabilities in IBM QRadar SIEM
- Information disclosure in IBM Cloud Pak for Multicloud Management Monitoring
- Multiple vulnerabilities in IBM InfoSphere Information Server
- Multiple vulnerabilities in IBM Application Performance Management
- Multiple vulnerabilities in IBM watsonx.data
- Fedora 28 update for hadoop
- Fedora 28 update for hadoop