Hitachi Vantara Pentaho Business Analytics Server Incorrect Authorization Vulnerability Allowing Access Control Bypass

Vulnerability

A vulnerability exists in Hitachi Vantara Pentaho Business Analytics Server in versions prior to 10.2.0.0 and 9.3.0.9, including 8.3.x. The issue arises because the product performs authorization checks when accessing resources or actions, but these checks are not applied correctly. This flaw enables attackers to bypass access restrictions. Additionally, the affected versions have modules enabled by default that permit the execution of system-level processes. The incorrect application of access control can result in unauthorized access to data or actions, potentially leading to information exposure and denial-of-service conditions.

Impact

Exploitation of this vulnerability can cause unauthorized access to restricted data or actions, leading to information exposure and possible denial-of-service situations.

Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM

Vulnerability Rating

Custom Algorithm
spread
3.1
impact
7.5
exploitability
5.2
remediation
7.7
relevance
0.0
threat
0.0
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.