Cross-Site Scripting Vulnerability in Hitachi Vantara Pentaho Business Analytics Server
CVE-2025-24909
Key Information:
- Vendor
- Hitachi
- Vendor
- CVE Published:
- 16 April 2025
Summary
The Hitachi Vantara Pentaho Business Analytics Server is susceptible to a Cross-Site Scripting (XSS) vulnerability. This flaw arises from the software's failure to adequately neutralize user-controllable input prior to incorporating it into web page outputs. Malicious actors can exploit this vulnerability to inject harmful scripts via the Analyzer plugin interface, affecting users by potentially stealing sensitive data such as cookies, which may carry session information. Furthermore, this vulnerability could allow an attacker to initiate unauthorized requests on behalf of victims, especially jeopardizing web management capabilities when the victim possesses administrator privileges.
Affected Version(s)
Pentaho Business Analytics Server 1.0 <= 9.3.*
Pentaho Business Analytics Server 10.0 < 10.2.0.2
References
CVSS V3.1
Timeline
Vulnerability published