Improper access control in Hadoop - CVE-2016-5393
Published: November 29, 2016 / Updated: August 9, 2020
Vulnerability identifier: #VU39999
CSH Severity: High
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2016-5393
CWE-ID: CWE-284
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote authenticated user to execute arbitrary code.
In Apache Hadoop 2.6.x before 2.6.5 and 2.7.x before 2.7.3, a remote user who can authenticate with the HDFS NameNode can possibly run arbitrary commands with the same privileges as the HDFS service.
Affected software
Hadoop
IBM InfoSphere Information Server
IBM InfoSphere Information Server
How to mitigate CVE-2016-5393
Install update from vendor's website.
IBM InfoSphere Information Server - update to 11.7.1.4 Service pack 1