PT-2025-7446 · Hitachi Vantara · Pentaho Data Integration & Analytics

Published

2024-06-06

·

Updated

2025-02-21

·

CVE-2024-5706

CVSS v2.0

9.0

High

VectorAV:N/AC:L/Au:S/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Hitachi Vantara Pentaho Data Integration & Analytics versions prior to 10.2.0.0 and 9.3.0.9, including 8.3.x
Description The product receives input from an upstream component but does not restrict or incorrectly restricts the input before it is used as an identifier for a resource that may be outside the intended sphere of control. This could allow an attacker to gain access to or modify sensitive data or system resources, potentially leading to remote code execution by unauthorized users.
Recommendations For versions prior to 10.2.0.0 and 9.3.0.9, including 8.3.x, update to version 10.2.0.0 or 9.3.0.9 or later to resolve the issue. As a temporary workaround, consider restricting access to the JNDI identifiers during the creation of Community Dashboards to minimize the risk of exploitation. Restrict access to sensitive data and system resources to prevent unauthorized access or modification.

Fix

RCE

Weakness Enumeration

Related Identifiers

BDU:2025-02159
CVE-2024-5706

Affected Products

Pentaho Data Integration & Analytics