4.3

CVE-2013-2193

Apache HBase 0.92.x before 0.92.3 and 0.94.x before 0.94.9, when the Kerberos features are enabled, allows man-in-the-middle attackers to disable bidirectional authentication and obtain sensitive information via unspecified vectors.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Apache ≫ Hbase Version 0.92.0
Apache ≫ Hbase Version 0.92.1
Apache ≫ Hbase Version 0.92.2
Apache ≫ Hbase Version 0.94.0
Apache ≫ Hbase Version 0.94.1
Apache ≫ Hbase Version 0.94.2
Apache ≫ Hbase Version 0.94.3
Apache ≫ Hbase Version 0.94.4
Apache ≫ Hbase Version 0.94.5
Apache ≫ Hbase Version 0.94.6
Apache ≫ Hbase Version 0.94.6.1
Apache ≫ Hbase Version 0.94.7
Apache ≫ Hbase Version 0.94.8
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.7% 0.483
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 4.3 3.2 6.4
AV:A/AC:H/Au:N/C:P/I:P/A:P
CWE-287 Improper Authentication

When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.

https://www.cloudera.com/documentation/other/security-bulletins/topics/csb_topic_1.html
http://osvdb.org/96615
http://seclists.org/fulldisclosure/2013/Aug/250