Vulnerabilities (CVE)

Filtered by vendor Cloudera Subscribe
Filtered by product Cloudera Manager
Total 22 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2014-8733 1 Cloudera 1 Cloudera Manager 2023-12-10 2.1 LOW N/A
Cloudera Manager 5.2.0, 5.2.1, and 5.3.0 stores the LDAP bind password in plaintext in unspecified world-readable files under /etc/hadoop, which allows local users to obtain this password.
CVE-2012-2230 1 Cloudera 2 Cloudera Manager, Cloudera Service And Configuration Manager 2023-12-10 6.5 MEDIUM N/A
Cloudera Manager 3.7.x before 3.7.5 and Service and Configuration Manager 3.5, when Kerberos is not enabled, does not properly install taskcontroller.cfg, which allows remote authenticated users to impersonate arbitrary user accounts via unspecified vectors, a different vulnerability than CVE-2012-1574.