CVE Vulnerabilities

CVE-2016-6815

Published: Oct 13, 2017 | Modified: Apr 20, 2025
CVSS 3.x
6.5
MEDIUM
Source:
NVD
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
CVSS 2.x
4 MEDIUM
AV:N/AC:L/Au:S/C:N/I:P/A:N
RedHat/V2
RedHat/V3
Ubuntu

In Apache Ranger before 0.6.2, users with keyadmin role should not be allowed to change password for users with admin role.

Affected Software

Name Vendor Start Version End Version
Ranger Apache 0.4.0 (including) 0.4.0 (including)
Ranger Apache 0.5.0 (including) 0.5.0 (including)
Ranger Apache 0.5.1 (including) 0.5.1 (including)
Ranger Apache 0.5.2 (including) 0.5.2 (including)
Ranger Apache 0.5.3 (including) 0.5.3 (including)
Ranger Apache 0.6.0 (including) 0.6.0 (including)
Ranger Apache 0.6.1 (including) 0.6.1 (including)

References