← Back

Pentaho Business Analytics

pentaho_business_analytics

Vendor: Hitachivantara • 4 CVEs

CVEs (4)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Hitachivantara
1Pentaho Business Analytics
Nov 21, 2024
Sep 27, 2023
N/A· v4
4.9 MEDIUM· v3
N/A· v2
Hitachi Vantara Pentaho Business Analytics Server prior to versions 9.5.0.0 and 9.3.0.4, including 8.3.x.x, saves passwords of the Hadoop Copy Files step in plaintext. 
1Hitachivantara
1Pentaho Business Analytics
Nov 21, 2024
Apr 11, 2023
N/A· v4
8.1 HIGH· v3
N/A· v2
Hitachi Vantara Pentaho Business Analytics Server versions before 9.3.0.0, 9.2.0.4 and 8.3.0.27 does not correctly perform an authorization check in the dashboard editor plugin API.   
1Hitachivantara
1Pentaho Business Analytics
Nov 21, 2024
Apr 11, 2023
N/A· v4
6.1 MEDIUM· v3
N/A· v2
Hitachi Vantara Pentaho Business Analytics Server prior to versions 9.3.0.0, 9.2.0.4 and 8.3.0.27 allow a malicious URL to inject content into a dashboard when the CDE plugin is present.   
1Hitachivantara
1Pentaho Business Analytics
May 13, 2026
Nov 28, 2017
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
In Hitachi Vantara Pentaho BA Platform through 8.0, a CSRF issue exists in the Business Analytics application.