Hitachi Vantara Pentaho Business Analytics Server
cpe:2.3:a:hitachi:vantara_pentaho_business_analytics_server:*:*:*:*:*:*:*
- < 10.2.0.0
- < 9.3.0.9
- ~8.3
A vulnerability exists in Hitachi Vantara Pentaho Business Analytics Server in versions prior to 10.2.0.0 and 9.3.0.9, including 8.3.x. The issue arises from access controls that are too broad, allowing unauthorized agents to access security-sensitive assets. Specifically, the authorization check in the user console trash content is insufficient, enabling attackers to bypass intended protections and gain unauthorized access.
Exploitation of this vulnerability allows for unauthorized access to security-sensitive assets by bypassing access control measures.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.