CVE-2016-4976: Apache Ambari

Medium severity, CVSS 5.5. EPSS: 0.5% chance of exploitation in the next 30 days.

Apache Ambari 2.x before 2.4.0 includes KDC administrator passwords on the kadmin command line, which allows local users to obtain sensitive information via a process listing.

Affected products

  • Apache Ambari: version 2.0.0 only; version 2.0.1 only; version 2.0.2 only; version 2.1.0 only; version 2.1.1 only; version 2.1.2 only; …

Published 2017-03-29. Last modified 2026-06-17.