Hitachi Vantara Pentaho Data Integration & Analytics是日本日立制作所(Hitachi)公司的一个数据集成与分析系统。 Hitachi Vantara Pentaho Data Integration & Analytics 10.2.0.2之前版本存在安全漏洞,该漏洞源于CGG Draw API未正确过滤用户输入路径,可能导致路径遍历攻击。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Hitachi Vantara | Pentaho Data Integration & Analytics | 1.0 ~ 9.3.* | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2025-0756 | 9.1 CRITICAL | Hitachi Vantara Pentaho Data Integration & Analytics - Improper Control of Resource Identi |
| CVE-2025-24908 | 6.8 MEDIUM | Hitachi Vantara Pentaho Data Integration & Analytics – Path Traversal |
| CVE-2025-0758 | 6.1 MEDIUM | Hitachi Vantara Pentaho Business Analytics Server - Incorrect Permission Assignment for Cr |
| CVE-2025-24911 | 4.9 MEDIUM | Hitachi Vantara Pentaho Business Analytics Server - Improper Restriction of XML External E |
| CVE-2025-24910 | 4.9 MEDIUM | Hitachi Vantara Pentaho Business Analytics Server - Improper Restriction of XML External E |
| CVE-2025-24909 | 4.4 MEDIUM | Hitachi Vantara Pentaho Business Analytics Server - Improper Neutralization of Input Durin |
| CVE-2025-0757 | 4.4 MEDIUM | Hitachi Vantara Pentaho Business Analytics Server - Improper Neutralization of Input Durin |
No comments yet