CVE-2015-6940: Infoleak
The GetResource servlet in Pentaho Business Analytics (BA) Suite 4.5.x, 4.8.x, and 5.0.x through 5.2.x and Pentaho Data Integration (PDI) Suite 4.3.x, 4.4.x, and 5.0.x through 5.2.x does not restrict access to files in the pentaho-solutions/system folder, which allows remote attackers to obtain passwords and other sensitive information via a file name in the resource parameter.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2015-6940?
CVE-2015-6940 is classified with a medium severity due to its potential for unauthorized access to sensitive files.
How do I fix CVE-2015-6940?
To fix CVE-2015-6940, update your Pentaho Business Analytics or Pentaho Data Integration to a version that addresses this vulnerability.
What does CVE-2015-6940 exploit?
CVE-2015-6940 exploits a lack of access controls on the GetResource servlet, allowing attackers to access files in the pentaho-solutions/system folder.
Which versions are affected by CVE-2015-6940?
CVE-2015-6940 affects Pentaho Business Analytics versions 4.5.x to 5.2.x and Pentaho Data Integration versions 4.3.x to 5.2.x.
Can CVE-2015-6940 lead to data breaches?
Yes, CVE-2015-6940 can lead to data breaches as it allows remote attackers to access potentially sensitive files.