CVE-2021-31601: High severity hitachi vantara vulnerability
An issue was discovered in Hitachi Vantara Pentaho through 9.1 and Pentaho Business Intelligence Server through 7.x. They implement a series of web services using the SOAP protocol to allow scripting interaction with the backend server. An authenticated user (regardless of privileges) can list all databases connection details and credentials.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2021-31601?
CVE-2021-31601 is classified as a medium severity vulnerability due to insufficient access controls in web services.
How do I fix CVE-2021-31601?
To mitigate CVE-2021-31601, update your Hitachi Vantara Pentaho or Pentaho Business Intelligence Server to the latest version that addresses this vulnerability.
What software versions are affected by CVE-2021-31601?
CVE-2021-31601 affects Hitachi Vantara Pentaho versions up to 9.1.0.0 and Pentaho Business Intelligence Server versions up to 7.1.
Who can exploit CVE-2021-31601?
CVE-2021-31601 can be exploited by any authenticated user, regardless of their privileges.
What type of vulnerability is CVE-2021-31601?
CVE-2021-31601 is an access control vulnerability that allows an authenticated user to list all data without proper privileges.