peter bassill · operator
$ cve CVE-2016-2002 JSON

CVE-2016-2002

9.8
CRITICAL · CVSS 3.0 · EPSS 3.1% (pctl 87)

In your normal cycle

Critical by CVSS (9.8), but no sign of active exploitation.

Description

The validateAdminConfig handler in the Analytics Management Console in HPE Vertica 7.0.x before 7.0.2.12, 7.1.x before 7.1.2-12, and 7.2.x before 7.2.2-1 allows remote attackers to execute arbitrary commands via the mcPort parameter, aka ZDI-CAN-3417.

Scoring

CVSS9.8 (CRITICAL, v3.0)
VectorCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS3.09% — more likely to be exploited than 87% of all CVEs
WeaknessCWE-77
On CISA KEVno
Public exploitnone known
Published2016-04-20
Last modified2026-06-17

Affected (1)

VendorProduct
opentextvertica

References

→ the Explorer  ·  watch your stack  ·  NVD