Insecure Credential Storage in Hitachi Vantara Pentaho Data Integration & Analytics
CVE-2024-37362
6.3MEDIUM
Key Information:
- Vendor
Hitachi
- Vendor
- CVE Published:
- 20 February 2025
What is CVE-2024-37362?
The Hitachi Vantara Pentaho Data Integration & Analytics product transmits and stores authentication credentials insecurely, making it vulnerable to unauthorized interception or retrieval. Adversaries could exploit this weakness by accessing sensitive information, such as database passwords stored when saving connections to services like RedShift. Without proper protection measures, such disclosure can lead to significant security risks, allowing further exploitation of the affected systems.
Affected Version(s)
Pentaho Business Analytics Server 1.0 < 9.3.0.8
Pentaho Data Integration & Analytics 10.0 < 10.2.0.0