CVE Vulnerabilities

CVE-2016-6815

Published: Oct 13, 2017 | Modified: Apr 20, 2025
CVSS 3.x
6.5
MEDIUM
Source:
NVD
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
CVSS 2.x
4 MEDIUM
AV:N/AC:L/Au:S/C:N/I:P/A:N
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

In Apache Ranger before 0.6.2, users with keyadmin role should not be allowed to change password for users with admin role.

Affected Software

NameVendorStart VersionEnd Version
RangerApache0.4.0 (including)0.4.0 (including)
RangerApache0.5.0 (including)0.5.0 (including)
RangerApache0.5.1 (including)0.5.1 (including)
RangerApache0.5.2 (including)0.5.2 (including)
RangerApache0.5.3 (including)0.5.3 (including)
RangerApache0.6.0 (including)0.6.0 (including)
RangerApache0.6.1 (including)0.6.1 (including)

References