ZeroHour

CVE-2021-31599

PoC
CVSS 3.1
8.8 high
EPSS
2%p83
Published
()
Modified
Description

An issue was discovered in Hitachi Vantara Pentaho through 9.1 and Pentaho Business Intelligence Server through 7.x. A reports (.prpt) file allows the inclusion of BeanShell scripts to ease the production of complex reports. An authenticated user can run arbitrary code.

Vendors
hitachi
Products
vantara pentaho, vantara pentaho business intelligence server
Weakness
CWE-434
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news