ZeroHour

CVE-2021-31601

PoC
CVSS 3.1
6.5 medium
EPSS
1%p70
Published
()
Modified
Description

An issue was discovered in Hitachi Vantara Pentaho through 9.1 and Pentaho Business Intelligence Server through 7.x. They implement a series of web services using the SOAP protocol to allow scripting interaction with the backend server. An authenticated user (regardless of privileges) can list all databases connection details and credentials.

Vendors
hitachi
Products
vantara pentaho, vantara pentaho business intelligence server
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

In the news