Vulnerabilities > Cloudera > Cloudera Manager > High

DATE CVE VULNERABILITY TITLE RISK
2019-11-26 CVE-2017-7399 Improper Privilege Management vulnerability in Cloudera Manager
Cloudera Manager 5.8.x before 5.8.5, 5.9.x before 5.9.2, and 5.10.x before 5.10.1 allows a read-only Cloudera Manager user to discover the usernames of other users and elevate the privileges of those users.
network
low complexity
cloudera CWE-269
8.8
2019-11-26 CVE-2015-6495 Information Exposure vulnerability in Cloudera Manager
There is Sensitive Information in Cloudera Manager before 5.4.6 Diagnostic Support Bundles.
network
low complexity
cloudera CWE-200
7.5
2019-07-11 CVE-2018-11744 Improper Access Control vulnerability in Cloudera Manager
Cloudera Manager through 5.15 has Incorrect Access Control.
network
high complexity
cloudera CWE-284
8.1
2019-07-03 CVE-2017-9326 Credentials Management vulnerability in Cloudera Manager 5.11.0
The keystore password for the Spark History Server may be exposed in unsecured files under the /var/run/cloudera-scm-agent directory managed by Cloudera Manager.
network
high complexity
cloudera CWE-255
7.5