Data Access Bypass in IBM InfoSphere BigInsights by Remote Authenticated Users
CVE-2015-1889
Currently unrated
Summary
The Big SQL component in IBM InfoSphere BigInsights versions 3.0 up to 3.0.0.2 is vulnerable to a security flaw that permits remote authenticated users to circumvent intended HDFS data-access restrictions. This can be achieved through the execution of a specially crafted CREATE HADOOP TABLE statement that references data belonging to an arbitrary user, or by importing a specific Hive table definition using the HCAT_SYNC_OBJECTS procedure, leading to unauthorized data exposure.
References
Timeline
Vulnerability published
Vulnerability Reserved