Security Advisory
CVE-2016-2174
CVE vulnerability detail - eXtreme Datacenter Security Operations
Description
SQL injection vulnerability in the policy admin tool in Apache Ranger before 0.5.3 allows remote authenticated administrators to execute arbitrary SQL commands via the eventTime parameter to service/plugins/policies/eventTime.