CRITICAL🇵🇱 Wersja polska

CVE-2016-2002

CVSS 9.8v3.0pub. 2016-04-20upd. 2026-05-06

The validateAdminConfig handler in the Analytics Management Console in HPE Vertica 7.0.x before 7.0.2.12, 7.1.x before 7.1.2-12, and 7.2.x before 7.2.2-1 allows remote attackers to execute arbitrary commands via the mcPort parameter, aka ZDI-CAN-3417.

CVSS Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
  • Opentext Vertica

    APP
    Opentext
    7.0.0 – 7.0.2.12 (excl.)7.1.0 – 7.1.2-12 (excl.)7.2.0 – 7.2.2-1 (excl.)
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
CWE
References

Related vulnerabilities

CVE-2017-5802CRITICAL9.8PL ✓same product

Zdalne przejęcie uprawnień w HPE Vertica Analytics Platform

CVE-2015-6867HIGH7.5same product

The vertica-udx-zygote process in HP Vertica 7.1.1 UDx does not require authentication, which allows remote at...

CVE-2025-12454MEDIUM5.1same product

Nieprawidłowa neutralizacja danych wejściowych podczas generowania strony internetowej (cross-site scripting) ...

CVE-2025-12455MEDIUM5.1same product

Podatność typu observable response discrepancy w OpenText Vertica umożliwia atak typu Password Brute Forcing. ...

CVE-2025-12453MEDIUM5.1same product

Podatność w OpenText Vertica polegająca na nieprawidłowym neutralizowaniu danych wejściowych podczas generowan...