Improper access control in Hadoop - CVE-2016-5393

 

Improper access control in Hadoop - CVE-2016-5393

Published: November 29, 2016 / Updated: August 9, 2020


Vulnerability identifier: #VU39999
CSH Severity: High
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2016-5393
CWE-ID: CWE-284
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote authenticated user to execute arbitrary code.

In Apache Hadoop 2.6.x before 2.6.5 and 2.7.x before 2.7.3, a remote user who can authenticate with the HDFS NameNode can possibly run arbitrary commands with the same privileges as the HDFS service.


Affected software

Hadoop
IBM InfoSphere Information Server

How to mitigate CVE-2016-5393

Install update from vendor's website.

IBM InfoSphere Information Server - update to 11.7.1.4 Service pack 1

External References

Related Security Bulletins