Hitachi Vantara Pentaho Business Analytics Server
cpe:2.3:a:hitachi:vantara_pentaho_business_analytics_server:*:*:*:*:*:*:*
- ~9.3
- ~8.3
A vulnerability exists in Hitachi Vantara Pentaho Business Analytics Server versions prior to 10.2.0.2, including 9.3.x and 8.3.x, where Karaf JMX beans are enabled and accessible by default. This configuration allows users with local execution privileges to access functionality exposed by these Karaf beans, potentially leading to unauthorized modification or reading of security-critical resources.
Exploitation of this vulnerability allows users with local execution privileges to access and manipulate functionality exposed by Karaf JMX beans, which could be used to modify or read sensitive resources within the application.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.