Insecure Credential Storage in Hitachi Vantara Pentaho Data Integration & Analytics
CVE-2024-37362
Key Information:
- Vendor
Hitachi
- Vendor
- CVE Published:
- 20 February 2025
What is CVE-2024-37362?
The Hitachi Vantara Pentaho Data Integration & Analytics product transmits and stores authentication credentials insecurely, making it vulnerable to unauthorized interception or retrieval. Adversaries could exploit this weakness by accessing sensitive information, such as database passwords stored when saving connections to services like RedShift. Without proper protection measures, such disclosure can lead to significant security risks, allowing further exploitation of the affected systems.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
Pentaho Business Analytics Server 1.0 < 9.3.0.8
Pentaho Data Integration & Analytics 10.0 < 10.2.0.0
References
CVSS V3.1
Timeline
Vulnerability published