PT-2022-12358 · Hitachi Vantara · Hitachi Vantara Pentaho Business Analytics Server
Published
2022-11-02
·
Updated
2023-07-21
·
CVE-2021-45446
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Hitachi Vantara Pentaho Business Analytics Server versions before 9.2.0.2 and 8.3.0.25
Description
A vulnerability in Hitachi Vantara Pentaho Business Analytics Server does not cascade the hidden property to the children of the Home folder. This directory listing provides an attacker with the complete index of all the resources located inside the directory.
Recommendations
For versions before 9.2.0.2, update to version 9.2.0.2 or later to resolve the issue.
For versions before 8.3.0.25, update to version 8.3.0.25 or later to resolve the issue.
Fix
Improper Preservation of Permissions
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Hitachi Vantara Pentaho Business Analytics Server