QID 983824

QID 983824: Java (maven) Security Update for org.apache.hbase:hbase (GHSA-p8xr-4v2c-rvgp)

Apache HBase 0.98 before 0.98.12.1, 1.0 before 1.0.1.1, and 1.1 before 1.1.0.1, as used in IBM InfoSphere BigInsights 3.0, 3.0.0.1, and 3.0.0.2 and other products, uses incorrect ACLs for ZooKeeper coordination state, which allows remote attackers to cause a denial of service (daemon outage), obtain sensitive information, or modify data via unspecified client traffic.

Successful exploitation of this vulnerability may affect the confidentiality, integrity, and availability of the targeted user.

  • CVSS V3 rated as High - 7.3 severity.
  • CVSS V2 rated as High - 7.5 severity.
  • Solution
    Customers are advised to refer to GHSA-p8xr-4v2c-rvgp for updates pertaining to this vulnerability.
    Vendor References

    CVEs related to QID 983824

    Software Advisories
    Advisory ID Software Component Link
    GHSA-p8xr-4v2c-rvgp org.apache.hbase:hbase URL Logo github.com/advisories/GHSA-p8xr-4v2c-rvgp