CVE-2016-2174

Publication date

2016-06-13 14:00:00

Family

redhat

State

PUBLISHED

Description

SQL injection vulnerability in the policy admin tool in Apache Ranger before 0.5.3 allows remote authenticated administrators to execute arbitrary SQL commands via the eventTime parameter to service/plugins/policies/eventTime.