Skip to main content

Vendor/product archive

apache / hbase CVEs

Beta · best-effort

6 CVEs tagged to apache / hbase0 Critical, 4 High, 2 Medium, 0 Low, 0 Unrated.

CVE-2026-49326

Published Jul 24, 2026

Missing Authorization vulnerability in Apache HBase thrift and rest delegation service. A scan operation in thrift/rest service has 3 steps, open, fetch(possible multiple times),…

CVSS 6.5 · Medium
evidence mentions
2
Buzz score
17.5
Vendor/product tagsBeta · best-effort

CVE-2019-0212

Published Mar 28, 2019

In all previously released Apache HBase 2.x versions (2.0.0-2.0.4, 2.1.0-2.1.3), authorization was incorrectly applied to users of the HBase REST server. Requests sent to the HBas…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2018-8025

Published Jun 27, 2018

CVE-2018-8025 describes an issue in Apache HBase that affects the optional "Thrift 1" API server when running over HTTP. There is a race-condition which could lead to authenticate…

CVSS 8.1 · High
Vendor/product tagsBeta · best-effort

CVE-2015-1836

Published Dec 21, 2015

Apache HBase 0.98 before 0.98.12.1, 1.0 before 1.0.1.1, and 1.1 before 1.1.0.1, as used in IBM InfoSphere BigInsights 3.0, 3.0.0.1, and 3.0.0.2 and other products, uses incorrect…

CVSS 7.3 · High
Vendor/product tagsBeta · best-effort

CVE-2013-2193

Published May 29, 2014

Apache HBase 0.92.x before 0.92.3 and 0.94.x before 0.94.9, when the Kerberos features are enabled, allows man-in-the-middle attackers to disable bidirectional authentication and…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort
Showing 1-6 of 6 CVEsPage 1 of 1