PT-2025-16918 · Hitachi Vantara · Hitachi Vantara Pentaho Business Analytics Server

Published

2025-04-16

·

Updated

2025-04-17

·

CVE-2025-24911

CVSS v3.1

4.9

Medium

VectorAV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Hitachi Vantara Pentaho Business Analytics Server versions prior to 10.2.0.2 Hitachi Vantara Pentaho Business Analytics Server versions 9.3.x Hitachi Vantara Pentaho Business Analytics Server versions 8.3.x
Description The issue concerns XML documents that contain a Document Type Definition (DTD), enabling the definition of XML entities. An entity can be defined by providing a substitution string in the form of a URI. Once the content of the URI is read, it is fed back into the application processing the XML, potentially exposing file contents. By submitting an XML file that defines an external entity with a file:// URI, an attacker can cause the processing application to read the contents of a local file. Using URIs with other schemes such as http://, the attacker can force the application to make outgoing requests to servers that the attacker cannot reach directly, which can be used to bypass firewall restrictions or hide the source of attacks.
Recommendations For Hitachi Vantara Pentaho Business Analytics Server versions prior to 10.2.0.2, update to version 10.2.0.2 or later to resolve the issue. For Hitachi Vantara Pentaho Business Analytics Server versions 9.3.x and 8.3.x, update to version 10.2.0.2 or later to resolve the issue. As a temporary workaround, consider restricting access to the Data Access XMLParserFactoryProducer to minimize the risk of exploitation.

Fix

XXE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2025-24911

Affected Products

Hitachi Vantara Pentaho Business Analytics Server