PT-2025-7445 · Hitachi Vantara · Hitachi Vantara Pentaho Business Analytics Server
Published
2025-02-19
·
Updated
2025-02-21
·
CVE-2024-5705
CVSS v2.0
9.0
High
| Vector | AV:N/AC:L/Au:S/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Hitachi Vantara Pentaho Business Analytics Server versions prior to 10.2.0.0 and 9.3.0.9, including 8.3.x
Description
The product does not correctly perform authorization checks when an actor attempts to access a resource or perform an action, allowing attackers to bypass intended access restrictions. This can lead to a wide range of problems, including information exposures and denial of service. When access control checks are incorrectly applied, users can access data or perform actions that they should not be allowed to perform.
Recommendations
For Hitachi Vantara Pentaho Business Analytics Server versions prior to 10.2.0.0 and 9.3.0.9, including 8.3.x, consider disabling the modules that allow execution of system level processes until a patch is available. Restrict access to sensitive data and actions to minimize the risk of exploitation. Update to version 10.2.0.0 or 9.3.0.9, or later, to resolve the issue.
Fix
DoS
Incorrect Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Hitachi Vantara Pentaho Business Analytics Server