Missing Authentication for Critical Function in Apache Hive - CVE-2021-34538
Published: May 24, 2023
Vulnerability details
The vulnerability allows a remote attacker to bypass authentication process.
The vulnerability exists due to CREATE() and DROP() function operations does not check for necessary authorization of involved entities in the query. A remote unauthenticated attacker can manipulate an existing UDF to drop and recreate UDFs pointing them to new jars that could be potentially malicious.
Affected software
IBM InfoSphere Information Server
IBM Operations Analytics Predictive Insights
QRadar User Behavior Analytics
IBM Cloud Pak for Watson AIOps
How to mitigate CVE-2021-34538
IBM Operations Analytics Predictive Insights - update to 1.3.6.8
QRadar User Behavior Analytics - update to 4.1.9
IBM Cloud Pak for Watson AIOps - update to 4.6.0
IBM InfoSphere Information Server - update to 11.7.1.4 Service pack 1