Hitachi Vantara Pentaho Business Analytics Server是日本日立制作所(Hitachi)公司的一个现代数据混合、集成和业务分析平台。 Hitachi Vantara Pentaho Business Analytics Server存在代码问题漏洞,该漏洞源于存在未验证传入HTTP/HTTPS请求的Host标头,导致攻击者可进行非法操作。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Hitachi Vantara | Pentaho Data Integration & Analytics | 10.0 ~ 10.2.0.0 | - |
|
| Hitachi Vantara | Pentaho Business Analytics Server | 1.0 ~ 9.3.0.9 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2024-37361 | 9.9 CRITICAL | Hitachi Vantara Pentaho Business Analytics Server - Deserialization of Untrusted Data |
| CVE-2024-5706 | 8.8 HIGH | Hitachi Vantara Pentaho Data Integration & Analytics - Improper Control of Resource Identi |
| CVE-2024-5705 | 8.8 HIGH | Hitachi Vantara Pentaho Business Analytics Server - Incorrect Authorization |
| CVE-2024-6697 | 6.5 MEDIUM | Hitachi Vantara Pentaho Business Analytics Server - Improper Handling of Insufficient Perm |
| CVE-2024-37363 | 6.5 MEDIUM | Hitachi Vantara Pentaho Business Analytics Server - Incorrect Authorization |
| CVE-2024-37362 | 6.3 MEDIUM | Hitachi Vantara Pentaho Data Integration & Analytics - Insufficiently Protected Credential |
| CVE-2024-6696 | 4.9 MEDIUM | Hitachi Vantara Pentaho Business Analytics Server - Insufficient Granularity of Access Con |
| CVE-2024-37360 | 4.4 MEDIUM | Hitachi Vantara Pentaho Business Analytics Server - Improper Neutralization of Input Durin |
No comments yet