Pentaho Server Vulnerable to URL Injection Attacks
CVE-2024-28984

6.1MEDIUM

Key Information:

Vendor
Hitachi Vantara
Status
Pentaho Business Analytics Server
Vendor
CVE Published:
26 June 2024

Summary

Hitachi Vantara Pentaho Business Analytics Server prior to versions 10.1.0.0 and 9.3.0.7, including 8.3.x allow a malicious URL to inject content into the Analyzer plugin interface.

References

CVSS V3.1

Score:
6.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

Collectors

NVD Database
.