CVE-2021-29215
Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
18/01/2022
Last modified:
26/01/2022
Description
A potential security vulnerability in HPE Ezmeral Data Fabric that may allow a remote access restriction bypass in the TEZ MapR ecosystem component was discovered in version(s): Prior to Tez-0.8: mapr-tez-0.8.201907081100-1.noarch; prior to Tez-0.9: mapr-tez-0.9.201907090334-1.noarch; prior to Tez-0.9.2: mapr-tez-0.9.2.0.201907081043-1.noarch. HPE has provided software updates to resolve the vulnerability in the TEZ MapR ecosystem component in HPE Ezmeral Data Fabric.
Impact
Base Score 3.x
9.80
Severity 3.x
CRITICAL
Base Score 2.0
7.50
Severity 2.0
HIGH
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:a:hpe:tez:*:*:*:*:*:*:*:* | 0.8 (including) | 0.8.201907081100-1.noarch (including) |
| cpe:2.3:a:hpe:tez:*:*:*:*:*:*:*:* | 0.9 (including) | 0.9.201907090334-1.noarch (excluding) |
| cpe:2.3:a:hpe:tez:*:*:*:*:*:*:*:* | 0.9.2 (including) | 0.9.2.0.201907081043-1.noarch (including) |
| cpe:2.3:a:hpe:ezmeral_data_fabric:-:*:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page



