CVE-2015-1772
Last modified
CVE-2015-1772 is a vulnerability of currently unknown severity. The LDAP implementation in HiveServer2 in Apache Hive before 1.0.1 and 1.1.x before 1.1.1, as used in IBM InfoSphere BigInsights 3.0, 3.0.0.1, and 3.0.0.2 and other products, mishandles simple unauthenticated and anonymous bind configurations, which allows remote attackers to bypass authentication via a crafted LDAP request.. EPSS estimates a 6.83% chance of exploitation in the next 30 days.
Description
The LDAP implementation in HiveServer2 in Apache Hive before 1.0.1 and 1.1.x before 1.1.1, as used in IBM InfoSphere BigInsights 3.0, 3.0.0.1, and 3.0.0.2 and other products, mishandles simple unauthenticated and anonymous bind configurations, which allows remote attackers to bypass authentication via a crafted LDAP request.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Ibm | Infosphere Biginsights | 3.0.0.0 |
| Ibm | Infosphere Biginsights | 3.0.0.1 |
| Ibm | Infosphere Biginsights | 3.0.0.2 |
| Apache | Hive | 1.0.0 |
| Apache | Hive | 1.1.0 |
References
- http://www-01.ibm.com/support/docview.wss?uid=swg21969546Vendor Advisory
- http://www-01.ibm.com/support/docview.wss?uid=swg21969546Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2015-1772?
How severe is CVE-2015-1772?
How do I fix CVE-2015-1772?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2015
- CVE-2015-1766Microsoft Internet Explorer 6 through 11 allows remote attac…
- CVE-2015-1767Microsoft Internet Explorer 9 through 11 allows remote attac…
- CVE-2015-1768win32k.sys in the kernel-mode drivers in Microsoft Windows S…
- CVE-2015-1769Mount Manager in Microsoft Windows Vista SP2, Windows Server…6.6
- CVE-2015-1770Microsoft Office 2013 SP1 and 2013 RT SP1 allows remote atta…8.8
- CVE-2015-1771Cross-site request forgery (CSRF) vulnerability in the web a…
- CVE-2015-1773Cross-site scripting (XSS) vulnerability in asdoc/templates/…
- CVE-2015-1774The HWP filter in LibreOffice before 4.3.7 and 4.4.x before …
- CVE-2015-1775Server-side request forgery (SSRF) vulnerability in the prox…
- CVE-2015-1776Apache Hadoop 2.6.x encrypts intermediate data generated by …
- CVE-2015-1777rhnreg_ks in Red Hat Network Client Tools (aka rhn-client-to…
- CVE-2015-1778The custom authentication realm used by karaf-tomcat's "open…
Are you affected by CVE-2015-1772?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
