CVE-2024-28983: Hitachi Vantara Pentaho Business Analytics Server - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
Hitachi Vantara Pentaho Business Analytics Server prior to versions 10.1.0.0 and 9.3.0.7, including 8.3.x allow a malicious URL to inject content into the Analyzer plugin interface.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-28983?
CVE-2024-28983 is classified as a moderate severity vulnerability due to its potential for unauthorized content injection.
How do I fix CVE-2024-28983?
To remediate CVE-2024-28983, upgrade your Hitachi Vantara Pentaho Business Analytics Server to versions 10.1.0.0 or 9.3.0.7 or later.
What systems are affected by CVE-2024-28983?
CVE-2024-28983 affects Hitachi Vantara Pentaho Business Analytics Server versions prior to 10.1.0.0 and 9.3.0.7, including 8.3.x.
What type of vulnerability is CVE-2024-28983?
CVE-2024-28983 is a cross-site scripting (XSS) vulnerability that allows malicious content injection into the Analyzer plugin interface.
How can CVE-2024-28983 impact my organization?
Exploitation of CVE-2024-28983 could allow attackers to manipulate page content, leading to phishing attacks or theft of sensitive data.