Ambari

Vendor:

First CVE: Nov 2, 2015 · Active for 10 years

26
Total CVEs
More Total CVEs than 95% of tracked products
3.3
Avg CVEs / Year
Higher CVE frequency than 81% of tracked products
6.8
Avg CVSS
Higher Avg CVSS than 36% of tracked products
0.0%
KEV Rate
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact Ambari over time

Volume of CVEsAvg CVSS Base Score
First CVE
Nov 2, 2015
10 years ago
Most Recent CVE
Jan 21, 2025
549 days ago

CVE Severity & Scoring

Ambari26 CVEs
All CVEs352,231 CVEs
LowMediumHighCritical
Attack Vector
Local2 (7.7%)
Network18 (69.2%)
Unknown6 (23.1%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low19 (73.1%)
High1 (3.8%)
Unknown6 (23.1%)
User Interaction
None18 (69.2%)
Unknown6 (23.1%)
Required2 (7.7%)
Privileges Required
Low9 (34.6%)
High1 (3.8%)
None10 (38.5%)
Unknown6 (23.1%)

Top CVEs

Signals from CVEs in this product scope (26 CVEs).

26 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
Custom commands may be executed on Ambari Agent (2.4.x, before 2.4.2) hosts without authorization, leading to unauthorized access to operations that may affect the underlying syste
Mar 28, 20179.831NONO
During installation of Ambari 2.4.0 through 2.4.2, Ambari Server artifacts are not created with proper ACLs.
Apr 3, 20179.830NONO
In Ambari 1.2.0 through 2.2.2, it may be possible to execute arbitrary system commands on the Ambari Server host while generating SSL certificates for hosts in an Ambari cluster.
Mar 29, 20179.830NONO
Malicious code injection in Apache Ambari in prior to 2.7.8. Users are recommended to upgrade to version 2.7.8, which fixes this issue. Impact: A Cluster Operator can manipulate t
Feb 27, 20248.828NONO
SpringEL injection in the server agent in Apache Ambari version 2.7.0 to 2.7.6 allows a malicious authenticated user to execute arbitrary code remotely. Users are recommended to up
Jul 12, 20238.827NONO
A code injection vulnerability exists in the Ambari Alert Definition feature, allowing authenticated users to inject and execute arbitrary shell commands. The vulnerability arise
Jan 21, 20258.826NONO
SpringEL injection in the metrics source in Apache Ambari version 2.7.0 to 2.7.6 allows a malicious authenticated user to execute arbitrary code remotely. Users are recommended to
Jul 12, 20238.826NONO
Apache Ambari, version 2.5.0 to 2.6.2, passwords for Hadoop credential stores are exposed in Ambari Agent informational log messages when the credential store feature is enabled fo
Jul 18, 20188.126NONO
A remote code injection vulnerability exists in the Ambari Metrics and AMS Alerts feature, allowing authenticated users to inject and execute arbitrary code. The vulnerability oc
Jan 21, 20258.825NONO
In Ambari 2.4.x (before 2.4.3) and Ambari 2.5.0, an authorized user of the Ambari Hive View may be able to gain unauthorized read access to files on the host where the Ambari serve
May 12, 20177.524NONO

Exploit Exposure

Signals from CVEs in this product scope (26 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

Signals from CVEs in this product scope (26 CVEs).

Media Mentions

Signals from CVEs in this product scope (26 CVEs).

Top CNAs Publishing CVEs For Ambari

Top CWEs

Versions

VersionCVE CountAvg CVSSAvg EPSSKEVExploits
2.5.026.72.1%00
2.4.227.32.0%00
2.4.147.82.1%00
2.4.048.02.1%00
2.2.226.31.7%00
2.2.115.50.5%00
2.2.015.50.5%00
2.1.215.50.5%00
2.1.115.50.5%00
2.1.035.92.5%00
2.0.235.62.5%00
2.0.155.42.5%00
2.0.055.42.5%00
1.7.045.33.0%00
1.6.115.52.9%00
1.6.015.52.9%00
1.5.115.52.9%00
1.5.015.52.9%00