Cross-Site Scripting Vulnerability in Hitachi Vantara Pentaho Business Analytics Server
CVE-2025-24909

4.4MEDIUM

Key Information:

Vendor
Hitachi
Vendor
CVE Published:
16 April 2025

Summary

The Hitachi Vantara Pentaho Business Analytics Server is susceptible to a Cross-Site Scripting (XSS) vulnerability. This flaw arises from the software's failure to adequately neutralize user-controllable input prior to incorporating it into web page outputs. Malicious actors can exploit this vulnerability to inject harmful scripts via the Analyzer plugin interface, affecting users by potentially stealing sensitive data such as cookies, which may carry session information. Furthermore, this vulnerability could allow an attacker to initiate unauthorized requests on behalf of victims, especially jeopardizing web management capabilities when the victim possesses administrator privileges.

Affected Version(s)

Pentaho Business Analytics Server 1.0 <= 9.3.*

Pentaho Business Analytics Server 10.0 < 10.2.0.2

References

CVSS V3.1

Score:
4.4
Severity:
MEDIUM
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

.