Security Advisory

CVE-2016-2174

7.2
HIGH

Vulnerability Description

SQL injection vulnerability in the policy admin tool in Apache Ranger before 0.5.3 allows remote authenticated administrators to execute arbitrary SQL commands via the eventTime parameter to service/plugins/policies/eventTime.
Published Date June 13, 2016
Official Source NIST NVD Advisory