PT-2024-22660 · Hitachi Vantara · Pentaho Data Integration & Analytics

Published

2024-09-11

·

Updated

2024-09-16

·

CVE-2024-28981

CVSS v3.1

8.5

High

VectorAV:N/AC:L/PR:L/UI:N/S:C/C:H/I:L/A:N
Name of the Vulnerable Software and Affected Versions Hitachi Vantara Pentaho Data Integration & Analytics versions prior to 10.1.0.0 Hitachi Vantara Pentaho Data Integration & Analytics versions prior to 9.3.0.8 Hitachi Vantara Pentaho Data Integration & Analytics version 8.3.x
Description The issue discloses database passwords when searching metadata injectable fields.
Recommendations For versions prior to 10.1.0.0, update to version 10.1.0.0 or later. For versions prior to 9.3.0.8, update to version 9.3.0.8 or later. For version 8.3.x, update to a version later than 8.3.x, such as 9.3.0.8 or 10.1.0.0.

Fix

Insufficiently Protected Credentials

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2025-02015
CVE-2024-28981

Affected Products

Pentaho Data Integration & Analytics