Hitachi Vantara Pentaho Business Analytics Server versions before 10.1.0.0 and 9.3.0.7, including 8.3.x do not correctly protect the ACL service endpoint of the Pentaho User Console against XML External Entity Reference.
Metrics
Affected Vendors & Products
History
Wed, 18 Sep 2024 14:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Hitachi
Hitachi pentaho Business Analytics Server |
|
CPEs | cpe:2.3:a:hitachi:pentaho_business_analytics_server:*:*:*:*:*:*:*:* | |
Vendors & Products |
Hitachi
Hitachi pentaho Business Analytics Server |

Status: PUBLISHED
Assigner: HITVAN
Published:
Updated: 2024-09-11T23:39:29.658Z
Reserved: 2024-03-13T19:18:14.913Z
Link: CVE-2024-28982

Updated: 2024-08-02T01:03:51.450Z

Status : Modified
Published: 2024-06-26T23:15:19.287
Modified: 2024-11-21T09:07:19.063
Link: CVE-2024-28982

No data.