Loading
The LDAP implementation in HiveServer2 in Apache Hive before 1.0.1 and 1.1.x before 1.1.1, as used in IBM InfoSphere BigInsights 3.0, 3.0.0.1, and 3.0.0.2 and other products, mishandles simple unauthenticated and anonymous bind configurations, which allows remote attackers to bypass authentication via a crafted LDAP request.
Use CWE-287, Ibm vendor hub and Infosphere Biginsights product page to widen CVE-2015-1772 into its surrounding weakness, vendor, and product context.
Compare it with CVE-2015-1947, CVE-2015-1836 and CVE-2014-4782 for nearby disclosures in the same product family.