← Back

CVE-2009-5100

nvd nist
Published: Sep 13, 2011Modified: Apr 29, 2026

JSON object

Loading...
2.1
Vector
AV:L/AC:L/Au:N/C:P/I:N/A:N
Exploitability: 3.9 / Impact: 2.9
Source: NVD

Description

Pentaho BI Server 1.7.0.1062 and earlier does not set the autocomplete tag to off on web pages using a password field, which might allow physically proximate attackers to obtain the password.

Affected (3)

Products: Pentaho: Bi Server
1 product
Bi Server
Configuration A
3 vulnerable
Vulnerable SoftwareAffected Versions
Pentaho
Up to 1.7.0.1062
Version 1.2.0
Version 1.6.0

Timeline

No history available yet.