Server-side Request Forgery in Hitachi Vantara Pentaho Business Analytics Server
CVE-2024-37359
8.6HIGH
Key Information:
- Vendor
- Hitachi
- Vendor
- CVE Published:
- 19 February 2025
Summary
The Hitachi Vantara Pentaho Business Analytics Server has a vulnerability that allows attackers to send crafted URLs to unexpected hosts. This occurs because the server fails to validate the Host header of incoming requests. As a result, malicious actors can exploit the server to conduct port scanning within internal networks, bypass firewall access controls, or even initiate requests using alternative protocols, potentially gaining unauthorized access to sensitive documents or resources.
Affected Version(s)
Pentaho Business Analytics Server 1.0 < 9.3.0.9
Pentaho Data Integration & Analytics 10.0 < 10.2.0.0
References
CVSS V3.1
Score:
8.6
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Changed
Timeline
Vulnerability published