Insufficient Access Control in Hitachi Vantara Pentaho Business Analytics Server
CVE-2024-6696
4.9MEDIUM
Key Information:
- Vendor
Hitachi
- Vendor
- CVE Published:
- 20 February 2025
What is CVE-2024-6696?
The Hitachi Vantara Pentaho Business Analytics Server exhibits a flaw in its access control implementation, allowing unauthorized agents to access sensitive assets. The access controls are too broad, failing to enforce necessary restrictions, leading to potential unauthorized actions within the system. This vulnerability affects versions prior to 10.2.0.0 and 9.3.0.9, as well as the 8.3.x series, highlighting the importance of stringent access control measures to safeguard sensitive information.
Affected Version(s)
Pentaho Business Analytics Server 1.0 < 9.3.0.9
Pentaho Data Integration & Analytics 10.0 < 10.2.0.0