PT-2025-7445 · Hitachi Vantara · Hitachi Vantara Pentaho Business Analytics Server

Published

2025-02-19

·

Updated

2025-02-21

·

CVE-2024-5705

CVSS v2.0

9.0

High

VectorAV:N/AC:L/Au:S/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Hitachi Vantara Pentaho Business Analytics Server versions prior to 10.2.0.0 and 9.3.0.9, including 8.3.x
Description The product does not correctly perform authorization checks when an actor attempts to access a resource or perform an action, allowing attackers to bypass intended access restrictions. This can lead to a wide range of problems, including information exposures and denial of service. When access control checks are incorrectly applied, users can access data or perform actions that they should not be allowed to perform.
Recommendations For Hitachi Vantara Pentaho Business Analytics Server versions prior to 10.2.0.0 and 9.3.0.9, including 8.3.x, consider disabling the modules that allow execution of system level processes until a patch is available. Restrict access to sensitive data and actions to minimize the risk of exploitation. Update to version 10.2.0.0 or 9.3.0.9, or later, to resolve the issue.

Fix

DoS

Incorrect Authorization

Weakness Enumeration

Related Identifiers

BDU:2025-02152
CVE-2024-5705

Affected Products

Hitachi Vantara Pentaho Business Analytics Server