There are vulnerabilities in various versions of Apache Hadoop that affect Apache Solr. The vulnerabilities are in Vulnerability Details section.
CVEID:CVE-2018-11766
**DESCRIPTION:**Apache Hadoop could allow a local attacker to gain elevated privileges on the system. By escalating to yarn user, an attacker could exploit this vulnerability to execute arbitrary commands on the system with root privileges.
CVSS Base score: 8.4
CVSS Temporal Score: See: https://exchange.xforce.ibmcloud.com/vulnerabilities/153346 for the current score.
CVSS Vector: (CVSS:3.0/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
CVEID:CVE-2017-15713
**DESCRIPTION:**Apache Hadoop could allow a remote authenticated attacker to obtain sensitive information. By using a specially-crafted file, a remote attacker could exploit this vulnerability to expose private files.
CVSS Base score: 4.3
CVSS Temporal Score: See: https://exchange.xforce.ibmcloud.com/vulnerabilities/138064 for the current score.
CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N)
Affected Product(s) | Version(s) |
---|---|
Log Analysis | 1.3.1 |
Log Analysis | 1.3.2 |
Log Analysis| 1.3.3
Log Analysis| 1.3.4
Log Analysis| 1.3.5
Log Analysis| 1.3.6
Principal Product and Version(s) : | Fix details |
---|---|
IBM Operations Analytics - Log Analysis version 1.3.x | Upgrade to Log Analysis version 1.3.7 |
Download the 1.3.7-TIV-IOALA-FP here |
None