ZeroHour

CVE-2022-43941

CVSS 3.1
6.5 medium
EPSS
<1%p43
Published
()
Modified
Description

Hitachi Vantara Pentaho Business Analytics Server versions before 9.4.0.1 and 9.3.0.2, including 8.3.x do not correctly protect the Post Analysis service endpoint of the data access plugin against out-of-band XML External Entity Reference.

Vendors
hitachi
Products
vantara pentaho business analytics server
Weakness
CWE-611
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

In the news

No ingested article mentions this CVE yet.