Vulnerabilities > Cloudera > Cloudera Manager > 4.1.4

DATE CVE VULNERABILITY TITLE RISK
2017-03-23 CVE-2015-2263 Permissions, Privileges, and Access Controls vulnerability in Cloudera Manager
Cloudera Manager 4.x, 5.0.x before 5.0.6, 5.1.x before 5.1.5, 5.2.x before 5.2.5, and 5.3.x before 5.3.3 uses global read permissions for files in its configuration directory when starting YARN NodeManager, which allows local users to obtain sensitive information by reading the files, as demonstrated by yarn.keytab or ssl-server.xml in /var/run/cloudera-scm-agent/process.
local
low complexity
cloudera CWE-264
2.1
2014-06-10 CVE-2014-0220 Information Exposure vulnerability in Cloudera Manager
Cloudera Manager before 4.8.3 and 5.x before 5.0.1 allows remote authenticated users to obtain sensitive configuration information via the API.
network
low complexity
cloudera CWE-200
4.0