Hitachi Vantara Pentaho Business Analytics Server versions before 10.1.0.0 and 9.3.0.7, including 8.3.x do not correctly protect the ACL service endpoint of the Pentaho User Console against XML External Entity Reference.
History

Wed, 18 Sep 2024 14:45:00 +0000

Type Values Removed Values Added
First Time appeared Hitachi
Hitachi pentaho Business Analytics Server
CPEs cpe:2.3:a:hitachi:pentaho_business_analytics_server:*:*:*:*:*:*:*:*
Vendors & Products Hitachi
Hitachi pentaho Business Analytics Server

cve-icon MITRE

Status: PUBLISHED

Assigner: HITVAN

Published: 2024-06-26T22:37:01.285Z

Updated: 2024-09-11T23:39:29.658Z

Reserved: 2024-03-13T19:18:14.913Z

Link: CVE-2024-28982

cve-icon Vulnrichment

Updated: 2024-08-02T01:03:51.450Z

cve-icon NVD

Status : Analyzed

Published: 2024-06-26T23:15:19.287

Modified: 2024-09-18T14:36:53.710

Link: CVE-2024-28982

cve-icon Redhat

No data.