Hitachi Vantara Pentaho Data Integration & Analytics
cpe:2.3:a:hitachi:pentaho_data_integration_and_analytics:*:*:*:*:*:*:*
- >= 8.3, < 8.4
- ~9.3
A vulnerability exists in Hitachi Vantara Pentaho Data Integration & Analytics versions prior to 10.2.0.0 and 9.3.0.8, including 8.3.x. The product improperly transmits or stores authentication credentials, specifically database passwords for RedShift connections, using an insecure method that allows for unauthorized interception or retrieval. This disclosure of sensitive information could lead to further exploitation.
The vulnerability could result in the unauthorized disclosure of database passwords, potentially allowing for unauthorized access to RedShift databases.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.