PT-2022-12358 · Hitachi Vantara · Hitachi Vantara Pentaho Business Analytics Server

Published

2022-11-02

·

Updated

2023-07-21

·

CVE-2021-45446

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Hitachi Vantara Pentaho Business Analytics Server versions before 9.2.0.2 and 8.3.0.25
Description A vulnerability in Hitachi Vantara Pentaho Business Analytics Server does not cascade the hidden property to the children of the Home folder. This directory listing provides an attacker with the complete index of all the resources located inside the directory.
Recommendations For versions before 9.2.0.2, update to version 9.2.0.2 or later to resolve the issue. For versions before 8.3.0.25, update to version 8.3.0.25 or later to resolve the issue.

Fix

Improper Preservation of Permissions

Weakness Enumeration

Related Identifiers

CVE-2021-45446

Affected Products

Hitachi Vantara Pentaho Business Analytics Server