Insufficient Access Control in Hitachi Vantara Pentaho Business Analytics Server
CVE-2024-6696
4.9MEDIUM
Key Information:
- Vendor
- Hitachi
- Vendor
- CVE Published:
- 20 February 2025
Summary
The Hitachi Vantara Pentaho Business Analytics Server exhibits a flaw in its access control implementation, allowing unauthorized agents to access sensitive assets. The access controls are too broad, failing to enforce necessary restrictions, leading to potential unauthorized actions within the system. This vulnerability affects versions prior to 10.2.0.0 and 9.3.0.9, as well as the 8.3.x series, highlighting the importance of stringent access control measures to safeguard sensitive information.
Affected Version(s)
Pentaho Business Analytics Server 1.0 < 9.3.0.9
Pentaho Data Integration & Analytics 10.0 < 10.2.0.0
References
CVSS V3.1
Score:
4.9
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published