Hitachi Vantara Pentaho Business Analytics Server versions before 9.3.0.0, 9.2.0.2 and
8.3.0.25 with the Data Lineage feature enabled transmits database passwords in clear text.
The transmission of sensitive data in clear text allows unauthorized actors with access to the
network to sniff and obtain sensitive information that can be later used to gain unauthorized
access.
Metrics
Affected Vendors & Products
References
Link | Providers |
---|---|
https://support.pentaho.com/hc/en-us/articles/6744504393101 |
History
No history.
MITRE
Status: PUBLISHED
Assigner: HITVAN
Published: 2022-11-02T14:56:01.585Z
Updated: 2024-08-04T04:39:20.773Z
Reserved: 2021-12-21T05:57:40.703Z
Link: CVE-2021-45447
Vulnrichment
No data.
NVD
Status : Modified
Published: 2022-11-02T15:15:10.247
Modified: 2024-11-21T06:32:13.613
Link: CVE-2021-45447
Redhat
No data.