CVE-2016-2174: Apache Ranger
High severity, CVSS 7.2. EPSS: 1.9% chance of exploitation in the next 30 days.
SQL injection vulnerability in the policy admin tool in Apache Ranger before 0.5.3 allows remote authenticated administrators to execute arbitrary SQL commands via the eventTime parameter to service/plugins/policies/eventTime.
Affected products
- Apache Ranger: version 0.5.0 only; version 0.5.1 only; version 0.5.2 only
Published 2016-06-13. Last modified 2026-06-17.