First published: Wed Jun 26 2024(Updated: )
Hitachi Vantara Pentaho Business Analytics Server versions before 10.1.0.0 and 9.3.0.7, including 8.3.x do not correctly protect the ACL service endpoint of the Pentaho User Console against XML External Entity Reference.
Credit: security.vulnerabilities@hitachivantara.com
Affected Software | Affected Version | How to fix |
---|---|---|
Hitachi Vantara Pentaho Business Intelligence Server | >=8.3.0<9.3.0.7 | |
Hitachi Vantara Pentaho Business Intelligence Server | >=9.3.1.0<10.1.0.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-28982 has a critical severity due to improper protection against XML External Entity Reference in affected versions.
To fix CVE-2024-28982, update the Hitachi Vantara Pentaho Business Analytics Server to version 10.1.0.0 or 9.3.0.7 or later.
The affected versions of Hitachi Vantara Pentaho Business Analytics Server include those before 10.1.0.0, 9.3.0.7, and 8.3.x.
CVE-2024-28982 can lead to potential information disclosure and unauthorized access due to the XML External Entity vulnerability.
Yes, CVE-2024-28982 can be exploited remotely if an attacker can access the ACL service endpoint of the Pentaho User Console.