Vulnerabilities
Vulnerable Software

Vulnerability Details CVE-2022-45855

SpringEL injection in the metrics source in Apache Ambari version 2.7.0 to 2.7.6 allows a malicious authenticated user to execute arbitrary code remotely. Users are recommended to upgrade to 2.7.7.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.002
EPSS Ranking 40.9%
CVSS Severity
CVSS v3 Score 8.0
Products affected by CVE-2022-45855
  • Apache » Ambari » Version: 2.7.0
    cpe:2.3:a:apache:ambari:2.7.0
  • Apache » Ambari » Version: 2.7.1
    cpe:2.3:a:apache:ambari:2.7.1
  • Apache » Ambari » Version: 2.7.3
    cpe:2.3:a:apache:ambari:2.7.3
  • Apache » Ambari » Version: 2.7.4
    cpe:2.3:a:apache:ambari:2.7.4
  • Apache » Ambari » Version: 2.7.5
    cpe:2.3:a:apache:ambari:2.7.5
  • Apache » Ambari » Version: 2.7.6
    cpe:2.3:a:apache:ambari:2.7.6


Contact Us

Shodan ® - All rights reserved