Hitachi Vantara Pentaho Business Analytics through 9.1 allows an unauthenticated user to execute arbitrary SQL queries on any Pentaho data source and thus retrieve data from the related databases, as demonstrated by an api/repos/dashboards/editor URI.
Metrics
Affected Vendors & Products
References
History
No history.
MITRE
Status: PUBLISHED
Assigner: mitre
Published: 2021-11-08T03:34:33
Updated: 2024-08-04T00:19:48.084Z
Reserved: 2021-06-14T00:00:00
Link: CVE-2021-34684
Vulnrichment
No data.
NVD
Status : Modified
Published: 2021-11-08T04:15:08.320
Modified: 2024-11-21T06:10:56.700
Link: CVE-2021-34684
Redhat
No data.