CVE-2024-28982
8.2
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H
Exploitability: 3.9 / Impact: 4.2
Source: NVD
Description
Hitachi Vantara Pentaho Business Analytics Server versions before 10.1.0.0 and 9.3.0.7, including 8.3.x do not correctly protect the ACL service endpoint of the Pentaho User Console against XML External Entity Reference.
Affected (2)
Products: Hitachi: Pentaho Business Analytics Server
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| From 8.3.0 to 9.3.0.7 |
References (2)
Source: security.vulnerabilities@hitachivantara.com
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Timeline
No history available yet.