PT-2021-19441 · Hitachi Vantara · Pentaho Business Intelligence Server+1
Published
2021-11-08
·
Updated
2022-07-12
·
CVE-2021-31601
CVSS v3.1
7.1
High
| Vector | AC:L/AV:N/A:N/C:H/I:L/PR:L/S:U/UI:N |
Name of the Vulnerable Software and Affected Versions
Hitachi Vantara Pentaho versions through 9.1
Pentaho Business Intelligence Server versions through 7.x
Description
An issue was discovered in the implementation of web services using the SOAP protocol, allowing scripting interaction with the backend server. An authenticated user, regardless of privileges, can list all databases connection details and credentials.
Recommendations
For Hitachi Vantara Pentaho versions through 9.1, consider restricting access to the SOAP web services until a fix is available.
For Pentaho Business Intelligence Server versions through 7.x, restrict access to the backend server to minimize the risk of exploitation.
As a temporary workaround, consider disabling the scripting interaction with the backend server until a patch is available.
Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Hitachi Vantara Pentaho
Pentaho Business Intelligence Server