Hitachi Vantara Pentaho Business Analytics Server
cpe:2.3:a:hitachi:vantara_pentaho_business_analytics_server:*:*:*:*:*:*:*
- < 10.2.0.2
- >= 9.3, < 9.4
- >= 8.3, < 8.4
A vulnerability exists in Hitachi Vantara Pentaho Business Analytics Server versions prior to 10.2.0.2, including 9.3.x and 8.3.x. The issue arises because the Data Access XMLParserFactoryProducer does not properly safeguard against out-of-band XML External Entity references. This flaw allows an attacker to exploit the XML parsing process by defining an external entity that points to a local file or an external server, potentially leading to unauthorized file access or manipulation of outgoing requests.
Exploitation of this vulnerability allows for arbitrary file reading from the server where Pentaho is running. Additionally, it could enable an attacker to make outgoing requests to external servers, bypassing firewall restrictions or obscuring the origin of certain attacks, such as port scanning.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.