CVE-2009-5099: XSS
Published Sep 13, 2011
·Updated
Cross-site scripting (XSS) vulnerability in ViewAction in Pentaho BI Server 1.7.0.1062 and earlier allows remote attackers to inject arbitrary web script or HTML via the outputType parameter.
Affected Software
3 affected components
Pentaho BI Server<=1.7.0.1062
Pentaho BI Server=1.2.0
Pentaho BI Server=1.6.0
Event History
Sep 13, 2011
CVE Published
via MITRE·07:00 PM
Data Sourced
via MITRE·07:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2009-5099?
CVE-2009-5099 is classified as a high severity cross-site scripting vulnerability.
2
How do I fix CVE-2009-5099?
To remediate CVE-2009-5099, upgrade to Pentaho BI Server version 1.7.0.1063 or later.
3
What systems are affected by CVE-2009-5099?
CVE-2009-5099 affects Pentaho BI Server versions up to and including 1.7.0.1062 and specific older versions like 1.2.0 and 1.6.0.
4
What does CVE-2009-5099 exploit?
CVE-2009-5099 exploits a vulnerability in the ViewAction component allowing attackers to inject arbitrary web scripts.
5
Is CVE-2009-5099 a common vulnerability?
CVE-2009-5099 is a known vulnerability in older versions of Pentaho BI Server and should be addressed promptly to prevent exploitation.