QID 375340
Date Published: 2021-03-26
QID 375340: HPE Ezmeral Data Fabric (MapR) Credentials Impersonation Vulnerability
MapR credentials can be compromised allowing the user to
escalate their privileges to act as any other user, including cluster administrators.
Impact on MapR users: All users who have enabled security on the
MapR platform are impacted and need to apply the appropriate patch
Affected Products:
All versions of MapR up to ver 6.0.1 are affected.
Note: All users who have enabled security on the MapR platform are the only impacted.
Potential detection as cannot confirm whether security feature on MapR platform is enabled or not.
QID Detection Logic:
This authenticated QID fetches the version of XStream library if it is installed via the package manager
on Unix based operating systems with commands such as dpkg -l and rpm -qa.
On successful exploit the attacker can escalate privileges.
CVEs related to QID 375340
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| Mapr | Linux |
|