Hitachi Vantara Pentaho Business Analytics Server
cpe:2.3:a:hitachi:vantara_pentaho_business_analytics_server:*:*:*:*:*:*:*
- >= 8.3, < 8.4
- ~9.3
- ~10.2
A vulnerability exists in Hitachi Vantara Pentaho Business Analytics Server in versions prior to 10.2.0.0 and 9.3.0.9, including 8.3.x. The issue arises because the application deserializes untrusted JSON data without properly validating it, allowing for the potential execution of unauthorized actions. This vulnerability is categorized under CWE-502, indicating a flaw related to the deserialization of untrusted data.
Exploitation of this vulnerability could lead to unauthorized actions being performed within the application, potentially allowing attackers to manipulate data or application behavior.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.