First published: Wed May 24 2023(Updated: )
Hitachi Vantara Pentaho Business Analytics Server versions before 9.4.0.1 and 9.3.0.3, including 8.3.x expose dashboard prompts to users who are not part of the authorization list.
Credit: security.vulnerabilities@hitachivantara.com
Affected Software | Affected Version | How to fix |
---|---|---|
Hitachi Vantara Pentaho Business Analytics Server | =9.4.0.0 | |
Hitachi Vantara Pentaho Business Analytics Server | >=9.3.0.0<=9.3.0.3 | |
Hitachi Vantara Pentaho | >=8.3.0.0<=8.3.0.25 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-1158 is a vulnerability in Hitachi Vantara Pentaho Business Analytics Server versions before 9.4.0.1 and 9.3.0.3, including 8.3.x, that exposes dashboard prompts to unauthorized users.
CVE-2023-1158 has a severity level of medium (4 out of 10).
CVE-2023-1158 allows unauthorized users to access dashboard prompts in Hitachi Vantara Pentaho Business Analytics Server versions before 9.4.0.1 and 9.3.0.3, including 8.3.x.
To fix CVE-2023-1158, it is recommended to upgrade to Hitachi Vantara Pentaho Business Analytics Server version 9.4.0.1 or 9.3.0.3, which have resolved the vulnerability.
More information about CVE-2023-1158 can be found at the following link: [Pentaho BA Server Incorrect Authorization](https://support.pentaho.com/hc/en-us/articles/14456024873741-IMPORTANT-Resolved-Pentaho-BA-Server-Incorrect-Authorization-Versions-before-9-4-0-1-and-9-3-0-3-including-8-3-x-Impacted-CVE-2023-1158-).