VendorsApacheambariall versions
Vulnerabilities

Apache Software Foundation Ambari

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

26CVEs
CVE-2016-6807
Custom commands may be executed on Ambari Agent (2.4.x, before 2.4.2) hosts without authorization, leading to unauthorized access to operations that may affect the underlying system. Such operations are invoked by the Ambari Agent process on Ambari Agent hosts, as the user executing the Ambari Agent process.
Published 2017-03-28 · Modified
9.8EPSS 0.024
CVE-2017-5642
During installation of Ambari 2.4.0 through 2.4.2, Ambari Server artifacts are not created with proper ACLs.
Published 2017-04-03 · Modified
9.8EPSS 0.019
CVE-2014-3582
In Ambari 1.2.0 through 2.2.2, it may be possible to execute arbitrary system commands on the Ambari Server host while generating SSL certificates for hosts in an Ambari cluster.
Published 2017-03-29 · Modified
9.8EPSS 0.016
CVE-2024-51941
Apache Ambari: Remote Code Injection in Ambari Metrics and AMS Alerts
Published 2025-01-21 · Analyzed
8.8EPSS 0.014
CVE-2025-23196
Apache Ambari: Code Injection Vulnerability in Ambari Alert Definition
Published 2025-01-21 · Analyzed
8.8EPSS 0.013
CVE-2022-45855
Apache Ambari: Allows authenticated metrics consumers to perform RCE
Published 2023-07-12 · Modified
8.8EPSS 0.012
CVE-2022-42009
Apache Ambari: A malicious authenticated user can remotely execute arbitrary code in the context of the application.
Published 2023-07-12 · Modified
8.8EPSS 0.012
CVE-2023-50379
Apache Ambari: authenticated users could perform command injection to perform RCE
Published 2024-02-27 · Analyzed
8.8EPSS 0.011
CVE-2018-8042
Apache Ambari, version 2.5.0 to 2.6.2, passwords for Hadoop credential stores are exposed in Ambari Agent informational log messages when the credential store feature is enabled for eligible services. For example, Hive and Oozie.
Published 2018-07-18 · Modified
8.1EPSS 0.018
CVE-2020-13924
In Apache Ambari versions 2.6.2.2 and earlier, malicious users can construct file names for directory traversal and traverse to other directories to download files.
Published 2021-03-17 · Modified
7.5EPSS 0.040
CVE-2017-5654
In Ambari 2.4.x (before 2.4.3) and Ambari 2.5.0, an authorized user of the Ambari Hive View may be able to gain unauthorized read access to files on the host where the Ambari server executes.
Published 2017-05-12 · Modified
7.5EPSS 0.022
CVE-2025-23195
Apache Ambari: XML External Entity (XXE) Vulnerability in Ambari/Oozie
Published 2025-01-21 · Analyzed
7.5EPSS 0.007
CVE-2015-3270
Apache Ambari before 2.0.2 or 2.1.x before 2.1.1 allows remote authenticated users to gain administrative privileges via unspecified vectors, possibly related to changing passwords.
Published 2015-11-02 · Modified
6.5EPSS 0.027
CVE-2017-5655
In Ambari 2.2.2 through 2.4.2 and Ambari 2.5.0, sensitive data may be stored on disk in temporary files on the Ambari Server host. The temporary files are readable by any user authenticated on the host.
Published 2017-05-15 · Modified
6.5EPSS 0.021
CVE-2023-50380
Apache Ambari: authenticated users could perform XXE to read arbitrary files on the server
Published 2024-02-27 · Modified
6.5EPSS 0.009
CVE-2020-1936
Stored XSS in Apache Ambari
Published 2021-03-02 · Modified
6.1EPSS 0.029
CVE-2023-50378
Apache Ambari: Various XSS problems
Published 2024-03-01 · Analyzed
6.1EPSS 0.012
CVE-2015-5210
Open redirect vulnerability in Apache Ambari before 2.1.2 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the targetURI parameter.
Published 2015-11-02 · Modified
5.8EPSS 0.041
CVE-2015-1775
Server-side request forgery (SSRF) vulnerability in the proxy endpoint (api/v1/proxy) in Apache Ambari before 2.1.0 allows remote authenticated users to conduct port scans and access unsecured services via a crafted REST call.
Published 2015-11-02 · Modified
5.5EPSS 0.030
CVE-2016-4976
Apache Ambari 2.x before 2.4.0 includes KDC administrator passwords on the kadmin command line, which allows local users to obtain sensitive information via a process listing.
Published 2017-03-29 · Modified
5.5EPSS 0.005
CVE-2018-8003
Apache Ambari, versions 1.4.0 to 2.6.1, is susceptible to a directory traversal attack allowing an unauthenticated user to craft an HTTP request which provides read-only access to any file on the filesystem of the host the Ambari Server runs on that is accessible by the user the Ambari Server is running as. Direct network access to the Ambari Server is required to issue this request, and those Ambari Servers that are protected behind a firewall, or in a restricted network zone are at less risk of being affected by this issue.
Published 2018-05-03 · Modified
5.3EPSS 0.042
CVE-2016-0731
The File Browser View in Apache Ambari before 2.2.1 allows remote authenticated administrators to read arbitrary files via a file: URL in the WebHDFS URL configuration.
Published 2016-05-18 · Modified
4.9EPSS 0.026
CVE-2015-4928
Apache Ambari before 2.1, as used in IBM Infosphere BigInsights 4.x before 4.1, includes cleartext passwords on a Configs screen, which allows physically proximate attackers to obtain sensitive information by reading password fields.
Published 2015-11-08 · Modified
4.3EPSS 0.028
CVE-2015-3186
Cross-site scripting (XSS) vulnerability in Apache Ambari before 2.1.0 allows remote authenticated cluster operator users to inject arbitrary web script or HTML via the note field in a configuration change.
Published 2015-11-02 · Modified
3.5EPSS 0.023
CVE-2016-0707
The agent in Apache Ambari before 2.1.2 uses weak permissions for the (1) /var/lib/ambari-agent/data and (2) /var/lib/ambari-agent/keys directories, which allows local users to obtain sensitive information by reading files in the directories.
Published 2016-05-18 · Modified
3.3EPSS 0.004
CVE-2015-4940
Apache Ambari before 2.1, as used in IBM Infosphere BigInsights 4.x before 4.1, stores a cleartext BigSheets password in a configuration file, which allows local users to obtain sensitive information by reading this file.
Published 2015-11-08 · Modified
2.1EPSS 0.007