← Back

Bi Server

bi_server

Vendor: Pentaho • 3 CVEs

CVEs (3)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Pentaho
1Bi Server
Apr 29, 2026
Sep 13, 2011
N/A· v4
N/A· v3
5.0 MEDIUM· v2
Pentaho BI Server 1.7.0.1062 and earlier includes the session ID (JSESSIONID) in the URL, which allows attackers to obtain it from session history, referer headers, or sniffing of web traffic.
1Pentaho
1Bi Server
Apr 29, 2026
Sep 13, 2011
N/A· v4
N/A· v3
2.1 LOW· v2
Pentaho BI Server 1.7.0.1062 and earlier does not set the autocomplete tag to off on web pages using a password field, which might allow physically proximate attackers to obtain the password.
1Pentaho
1Bi Server
Apr 29, 2026
Sep 13, 2011
N/A· v4
N/A· v3
4.3 MEDIUM· v2
Cross-site scripting (XSS) vulnerability in ViewAction in Pentaho BI Server 1.7.0.1062 and earlier allows remote attackers to inject arbitrary web script or HTML via the outputType parameter.