CVE-2021-31599: Malicious File Upload
An issue was discovered in Hitachi Vantara Pentaho through 9.1 and Pentaho Business Intelligence Server through 7.x. A reports (.prpt) file allows the inclusion of BeanShell scripts to ease the production of complex reports. An authenticated user can run arbitrary code.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID for this issue in Hitachi Vantara Pentaho?
The vulnerability ID is CVE-2021-31599.
What is the severity rating for CVE-2021-31599?
The severity rating for CVE-2021-31599 is 8.8 (High).
What is the affected software for CVE-2021-31599?
The affected software for CVE-2021-31599 is Hitachi Vantara Pentaho through version 9.1 and Pentaho Business Intelligence Server through version 7.x.
What is the vulnerability description for CVE-2021-31599?
CVE-2021-31599 is a vulnerability in Hitachi Vantara Pentaho and Pentaho Business Intelligence Server that allows an authenticated user to run arbitrary code by including BeanShell scripts in a reports (.prpt) file.
Are there any references available for CVE-2021-31599?
Yes, you can find references for CVE-2021-31599 at the following links: [Packet Storm Security](http://packetstormsecurity.com/files/164772/Pentaho-Business-Analytics-Pentaho-Business-Server-9.1-Remote-Code-Execution.html) and [Hitachi Vantara Security](https://www.hitachi.com/hirt/security/index.html).