Hitachi Vantara Pentaho Data Integration & Analytics versions before 9.5.0.1 and 9.3.0.5, including
8.3.x does not restrict JNDI identifiers during the creation of XActions, allowing control of system level data sources.

Advisories
Source ID Title
EUVD EUVD EUVD-2023-44175 Hitachi Vantara Pentaho Data Integration & Analytics versions before 9.5.0.1 and 9.3.0.5, including 8.3.x does not restrict JNDI identifiers during the creation of XActions, allowing control of system level data sources.
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: HITVAN

Published:

Updated: 2024-08-02T06:55:03.685Z

Reserved: 2023-07-05T16:19:15.295Z

Link: CVE-2023-3517

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2023-12-12T23:15:07.003

Modified: 2024-11-21T08:17:26.280

Link: CVE-2023-3517

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.