Lucene search

K
cve[email protected]CVE-2015-1775
HistoryNov 02, 2015 - 7:59 p.m.

CVE-2015-1775

2015-11-0219:59:00
web.nvd.nist.gov
21
cve-2015-1775
server-side request forgery
ssrf vulnerability
apache ambari
port scans
unsecured services
crafted rest call

5.5 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

SINGLE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:L/Au:S/C:P/I:P/A:N

6.4 Medium

AI Score

Confidence

Low

0.003 Low

EPSS

Percentile

65.8%

Server-side request forgery (SSRF) vulnerability in the proxy endpoint (api/v1/proxy) in Apache Ambari before 2.1.0 allows remote authenticated users to conduct port scans and access unsecured services via a crafted REST call.

Affected configurations

NVD
Node
apacheambariMatch1.5.0
OR
apacheambariMatch1.5.1
OR
apacheambariMatch1.6.0
OR
apacheambariMatch1.6.1
OR
apacheambariMatch1.7.0
OR
apacheambariMatch2.0.0
OR
apacheambariMatch2.0.1
OR
apacheambariMatch2.0.2

5.5 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

SINGLE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:L/Au:S/C:P/I:P/A:N

6.4 Medium

AI Score

Confidence

Low

0.003 Low

EPSS

Percentile

65.8%

Related for CVE-2015-1775