Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1325 CNY

100%

Pentaho Data Integration & Analytics — Vulnerabilities & Security Advisories 15

All 15 CVE vulnerabilities found in Pentaho Data Integration & Analytics, with AI-generated Chinese analysis, references, and POCs.

This page provides a comprehensive aggregation of vulnerability records associated with Pentaho Data Integration & Analytics, categorized by Common Weakness Enumerations (CWE) and specific security tags. It serves as a centralized repository for security professionals, developers, and system administrators seeking to understand the attack surface and historical security posture of this widely used business intelligence platform. The collection encompasses a broad spectrum of security issues affecting the product, including but not limited to cross-site scripting, SQL injection, improper access control, and insecure default configurations. The timeline covered spans from the initial public disclosures of critical flaws in early releases up to the most recent advisories published by the vendor and independent researchers. This ensures a continuous view of the product's evolving security landscape, capturing both legacy issues and newly identified risks in current versions. Visitors to this resource can effectively track a vendor’s advisory history to identify response patterns and patching velocities. Users can also delve into specific weakness classes to understand the underlying technical root causes of vulnerabilities within the Pentaho ecosystem. Additionally, the page allows for a detailed lookup of a product’s vulnerability history, enabling teams to correlate security incidents with specific software versions and release cycles. This data supports informed decision-making for risk assessment, compliance auditing, and strategic upgrade planning, ensuring that stakeholders have a clear, evidence-based perspective on the security maturity of Pentaho Data Integration & Analytics over time.

Vendor: Hitachi Vantara

CVE IDTitleCVSSSeverityPublished
CVE-2025-24907 Hitachi Vantara Pentaho Data Integration & Analytics – Path Traversal CWE-35 6.8 Medium2025-04-16
CVE-2025-24908 Hitachi Vantara Pentaho Data Integration & Analytics – Path Traversal CWE-35 6.8 Medium2025-04-16
CVE-2025-0756 Hitachi Vantara Pentaho Data Integration & Analytics - Improper Control of Resource Identifiers ('Resource Injection') CWE-99 9.1 Critical2025-04-16
CVE-2024-37363 Hitachi Vantara Pentaho Business Analytics Server - Incorrect Authorization CWE-862 6.5 Medium2025-02-19
CVE-2024-37362 Hitachi Vantara Pentaho Data Integration & Analytics - Insufficiently Protected Credentials CWE-522 6.3 Medium2025-02-19
CVE-2024-6697 Hitachi Vantara Pentaho Business Analytics Server - Improper Handling of Insufficient Permissions or Privileges CWE-280 6.5 Medium2025-02-19
CVE-2024-6696 Hitachi Vantara Pentaho Business Analytics Server - Insufficient Granularity of Access Control CWE-1220 4.9 Medium2025-02-19
CVE-2024-37361 Hitachi Vantara Pentaho Business Analytics Server - Deserialization of Untrusted Data CWE-502 9.9 Critical2025-02-19
CVE-2024-37360 Hitachi Vantara Pentaho Business Analytics Server - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') CWE-79 4.4 Medium2025-02-19
CVE-2024-37359 Hitachi Vantara Pentaho Business Analytics Server – Server Side Request Forgery CWE-918 8.6 High2025-02-19
CVE-2024-5705 Hitachi Vantara Pentaho Business Analytics Server - Incorrect Authorization CWE-863 8.8 High2025-02-19
CVE-2024-5706 Hitachi Vantara Pentaho Data Integration & Analytics - Improper Control of Resource Identifiers ('Resource Injection') CWE-99 8.8 High2025-02-19
CVE-2024-28981 Hitachi Vantara Pentaho Data Integration & Analytics - Insufficiently Protected Credentials CWE-522 8.5 High2024-09-11
CVE-2023-5617 Hitachi Vantara Pentaho Data Integration & Analytics - Server-generated Error Message Containing Sensitive Information CWE-550 5.3 Medium2024-02-28
CVE-2023-3517 Hitachi Vantara Pentaho Data Integration & Analytics - Improper Control of Resource Identifiers ('Resource Injection') CWE-99 8.5 High2023-12-12

All 15 known CVE vulnerabilities affecting Pentaho Data Integration & Analytics with full Chinese analysis, references, and POCs where available.