Hitachi Vantara Pentaho Business Analytics Server
cpe:2.3:a:hitachi:vantara_pentaho_business_analytics_server:*:*:*:*:*:*:*
- < 10.2.0.2
- >= 9.3, < 9.4
- >= 8.3, < 8.4
A vulnerability exists in Hitachi Vantara Pentaho Business Analytics Server versions prior to 10.2.0.2, including 9.3.x and 8.3.x. The issue arises because the application does not properly safeguard the Pentaho Data Integration MessageSourceCrawler against out-of-band XML External Entity references. This flaw allows an attacker to exploit the XML parsing process by defining an external entity that points to a local file or an external server, potentially leading to unauthorized file access or manipulation of outgoing requests.
Exploitation of this vulnerability allows for unauthorized reading of local files or manipulation of outgoing requests to external servers, which could be used to bypass firewall restrictions or obscure the source of certain attacks, such as port scanning.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.