Hitachi Vantara Pentaho Business Analytics Server versions before 10.1.0.0 and 9.3.0.7, including 8.3.x do not correctly protect the ACL service endpoint of the Pentaho User Console against XML External Entity Reference.
Metrics
Affected Vendors & Products
History
Wed, 18 Sep 2024 14:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Hitachi
Hitachi pentaho Business Analytics Server |
|
CPEs | cpe:2.3:a:hitachi:pentaho_business_analytics_server:*:*:*:*:*:*:*:* | |
Vendors & Products |
Hitachi
Hitachi pentaho Business Analytics Server |
MITRE
Status: PUBLISHED
Assigner: HITVAN
Published: 2024-06-26T22:37:01.285Z
Updated: 2024-09-11T23:39:29.658Z
Reserved: 2024-03-13T19:18:14.913Z
Link: CVE-2024-28982
Vulnrichment
Updated: 2024-08-02T01:03:51.450Z
NVD
Status : Modified
Published: 2024-06-26T23:15:19.287
Modified: 2024-11-21T09:07:19.063
Link: CVE-2024-28982
Redhat
No data.