VendorsApacheambariany version
Vulnerabilities

Apache Software Foundation Ambari any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

19CVEs
CVE-2014-3582
In Ambari 1.2.0 through 2.2.2, it may be possible to execute arbitrary system commands on the Ambari Server host while generating SSL certificates for hosts in an Ambari cluster.
Published 2017-03-29 · Modified
9.8EPSS 0.016
CVE-2024-51941
Apache Ambari: Remote Code Injection in Ambari Metrics and AMS Alerts
Published 2025-01-21 · Analyzed
8.8EPSS 0.014
CVE-2025-23196
Apache Ambari: Code Injection Vulnerability in Ambari Alert Definition
Published 2025-01-21 · Analyzed
8.8EPSS 0.013
CVE-2022-45855
Apache Ambari: Allows authenticated metrics consumers to perform RCE
Published 2023-07-12 · Modified
8.8EPSS 0.012
CVE-2022-42009
Apache Ambari: A malicious authenticated user can remotely execute arbitrary code in the context of the application.
Published 2023-07-12 · Modified
8.8EPSS 0.012
CVE-2023-50379
Apache Ambari: authenticated users could perform command injection to perform RCE
Published 2024-02-27 · Analyzed
8.8EPSS 0.011
CVE-2018-8042
Apache Ambari, version 2.5.0 to 2.6.2, passwords for Hadoop credential stores are exposed in Ambari Agent informational log messages when the credential store feature is enabled for eligible services. For example, Hive and Oozie.
Published 2018-07-18 · Modified
8.1EPSS 0.018
CVE-2020-13924
In Apache Ambari versions 2.6.2.2 and earlier, malicious users can construct file names for directory traversal and traverse to other directories to download files.
Published 2021-03-17 · Modified
7.5EPSS 0.040
CVE-2025-23195
Apache Ambari: XML External Entity (XXE) Vulnerability in Ambari/Oozie
Published 2025-01-21 · Analyzed
7.5EPSS 0.007
CVE-2023-50380
Apache Ambari: authenticated users could perform XXE to read arbitrary files on the server
Published 2024-02-27 · Modified
6.5EPSS 0.009
CVE-2020-1936
Stored XSS in Apache Ambari
Published 2021-03-02 · Modified
6.1EPSS 0.029
CVE-2023-50378
Apache Ambari: Various XSS problems
Published 2024-03-01 · Analyzed
6.1EPSS 0.012
CVE-2015-5210
Open redirect vulnerability in Apache Ambari before 2.1.2 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the targetURI parameter.
Published 2015-11-02 · Modified
5.8EPSS 0.041
CVE-2018-8003
Apache Ambari, versions 1.4.0 to 2.6.1, is susceptible to a directory traversal attack allowing an unauthenticated user to craft an HTTP request which provides read-only access to any file on the filesystem of the host the Ambari Server runs on that is accessible by the user the Ambari Server is running as. Direct network access to the Ambari Server is required to issue this request, and those Ambari Servers that are protected behind a firewall, or in a restricted network zone are at less risk of being affected by this issue.
Published 2018-05-03 · Modified
5.3EPSS 0.042
CVE-2016-0731
The File Browser View in Apache Ambari before 2.2.1 allows remote authenticated administrators to read arbitrary files via a file: URL in the WebHDFS URL configuration.
Published 2016-05-18 · Modified
4.9EPSS 0.026
CVE-2015-4928
Apache Ambari before 2.1, as used in IBM Infosphere BigInsights 4.x before 4.1, includes cleartext passwords on a Configs screen, which allows physically proximate attackers to obtain sensitive information by reading password fields.
Published 2015-11-08 · Modified
4.3EPSS 0.028
CVE-2015-3186
Cross-site scripting (XSS) vulnerability in Apache Ambari before 2.1.0 allows remote authenticated cluster operator users to inject arbitrary web script or HTML via the note field in a configuration change.
Published 2015-11-02 · Modified
3.5EPSS 0.023
CVE-2016-0707
The agent in Apache Ambari before 2.1.2 uses weak permissions for the (1) /var/lib/ambari-agent/data and (2) /var/lib/ambari-agent/keys directories, which allows local users to obtain sensitive information by reading files in the directories.
Published 2016-05-18 · Modified
3.3EPSS 0.004
CVE-2015-4940
Apache Ambari before 2.1, as used in IBM Infosphere BigInsights 4.x before 4.1, stores a cleartext BigSheets password in a configuration file, which allows local users to obtain sensitive information by reading this file.
Published 2015-11-08 · Modified
2.1EPSS 0.007