PT-2021-19441 · Hitachi Vantara · Pentaho Business Intelligence Server+1

Published

2021-11-08

·

Updated

2022-07-12

·

CVE-2021-31601

CVSS v3.1

7.1

High

VectorAC:L/AV:N/A:N/C:H/I:L/PR:L/S:U/UI:N
Name of the Vulnerable Software and Affected Versions Hitachi Vantara Pentaho versions through 9.1 Pentaho Business Intelligence Server versions through 7.x
Description An issue was discovered in the implementation of web services using the SOAP protocol, allowing scripting interaction with the backend server. An authenticated user, regardless of privileges, can list all databases connection details and credentials.
Recommendations For Hitachi Vantara Pentaho versions through 9.1, consider restricting access to the SOAP web services until a fix is available. For Pentaho Business Intelligence Server versions through 7.x, restrict access to the backend server to minimize the risk of exploitation. As a temporary workaround, consider disabling the scripting interaction with the backend server until a patch is available.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2021-31601

Affected Products

Hitachi Vantara Pentaho
Pentaho Business Intelligence Server