PT-2024-22661 · Hitachi Vantara · Pentaho Business Analytics Server

Published

2024-06-26

·

Updated

2024-09-18

·

CVE-2024-28982

CVSS v3.1

8.2

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H
Name of the Vulnerable Software and Affected Versions Hitachi Vantara Pentaho Business Analytics Server versions prior to 10.1.0.0 Hitachi Vantara Pentaho Business Analytics Server versions prior to 9.3.0.7 Hitachi Vantara Pentaho Business Analytics Server version 8.3.x
Description The issue arises from the incorrect protection of the ACL service endpoint of the Pentaho User Console against XML External Entity Reference. This allows for potential exploitation.
Recommendations For versions prior to 10.1.0.0, update to version 10.1.0.0 or later. For versions prior to 9.3.0.7, update to version 9.3.0.7 or later. For version 8.3.x, consider disabling the ACL service endpoint of the Pentaho User Console as a temporary workaround until a patch is available.

Fix

XML Entity Expansion

Weakness Enumeration

Related Identifiers

CVE-2024-28982

Affected Products

Pentaho Business Analytics Server