PT-2025-16918 · Hitachi Vantara · Hitachi Vantara Pentaho Business Analytics Server
Published
2025-04-16
·
Updated
2025-04-17
·
CVE-2025-24911
CVSS v3.1
4.9
Medium
| Vector | AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Hitachi Vantara Pentaho Business Analytics Server versions prior to 10.2.0.2
Hitachi Vantara Pentaho Business Analytics Server versions 9.3.x
Hitachi Vantara Pentaho Business Analytics Server versions 8.3.x
Description
The issue concerns XML documents that contain a Document Type Definition (DTD), enabling the definition of XML entities. An entity can be defined by providing a substitution string in the form of a URI. Once the content of the URI is read, it is fed back into the application processing the XML, potentially exposing file contents. By submitting an XML file that defines an external entity with a file:// URI, an attacker can cause the processing application to read the contents of a local file. Using URIs with other schemes such as http://, the attacker can force the application to make outgoing requests to servers that the attacker cannot reach directly, which can be used to bypass firewall restrictions or hide the source of attacks.
Recommendations
For Hitachi Vantara Pentaho Business Analytics Server versions prior to 10.2.0.2, update to version 10.2.0.2 or later to resolve the issue.
For Hitachi Vantara Pentaho Business Analytics Server versions 9.3.x and 8.3.x, update to version 10.2.0.2 or later to resolve the issue.
As a temporary workaround, consider restricting access to the Data Access XMLParserFactoryProducer to minimize the risk of exploitation.
Fix
XXE
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Hitachi Vantara Pentaho Business Analytics Server