Out-of-band XML External Entity Reference Vulnerability in Hitachi Vantara Pentaho Business Analytics Server
CVE-2025-24910
Key Information:
- Vendor
Hitachi
- Vendor
- CVE Published:
- 16 April 2025
What is CVE-2025-24910?
The Hitachi Vantara Pentaho Business Analytics Server prior to version 10.2.0.2, including versions 9.3.x and 8.3.x, is vulnerable to an out-of-band XML External Entity Reference. This vulnerability allows attackers to craft XML files that define external entities, which, when processed by the server, can lead to unintentional disclosure of local file contents or the ability to initiate requests to external servers. Such actions can enable attackers to bypass security measures, facilitating unauthorized access to sensitive information and avenues for further attacks.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
Pentaho Business Analytics Server 1.0 <= 9.3.*
Pentaho Business Analytics Server 10.0 < 10.2.0.2
References
CVSS V3.1
Timeline
Vulnerability published