Data Access Bypass in IBM InfoSphere BigInsights by Remote Authenticated Users
CVE-2015-1889

Currently unrated

Key Information:

Vendor
IBM
Vendor
CVE Published:
22 April 2015

Summary

The Big SQL component in IBM InfoSphere BigInsights versions 3.0 up to 3.0.0.2 is vulnerable to a security flaw that permits remote authenticated users to circumvent intended HDFS data-access restrictions. This can be achieved through the execution of a specially crafted CREATE HADOOP TABLE statement that references data belonging to an arbitrary user, or by importing a specific Hive table definition using the HCAT_SYNC_OBJECTS procedure, leading to unauthorized data exposure.

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.