Cleartext Password Exposure in IBM Infosphere BigInsights via Apache Ambari
CVE-2015-4928

Currently unrated

Key Information:

Vendor
Apache
Status
Vendor
CVE Published:
8 November 2015

Summary

The vulnerability exists in Apache Ambari prior to version 2.1, utilized within IBM Infosphere BigInsights versions 4.x prior to 4.1. It enables physical attackers with close proximity to access sensitive information by reading exposed password fields on the Configs screen. This flaw potentially compromises data security, allowing unauthorized access to confidential credentials.

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.