ZeroHour

CVE-2024-28982

CVSS 3.1
8.2 high
EPSS
<1%p31
Published
()
Modified
Description

Hitachi Vantara Pentaho Business Analytics Server versions before 10.1.0.0 and 9.3.0.7, including 8.3.x do not correctly protect the ACL service endpoint of the Pentaho User Console against XML External Entity Reference.

Vendors
hitachi
Products
pentaho business analytics server
Weakness
CWE-776
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H

In the news

No ingested article mentions this CVE yet.