« Volver al listado

CVE-2015-6940

Estado: ModificadaMedia (5)—

The GetResource servlet in Pentaho Business Analytics (BA) Suite 4.5.x, 4.8.x, and 5.0.x through 5.2.x and Pentaho Data Integration (PDI) Suite 4.3.x, 4.4.x, and 5.0.x through 5.2.x does not restrict access to files in the pentaho-solutions/system folder, which allows remote attackers to obtain passwords and other sensitive information via a file name in the resource parameter.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (2)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2015-6940",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 5,
          "accessVector": "NETWORK",
          "vectorString": "AV:N/AC:L/Au:N/C:P/I:N/A:N",
          "authentication": "NONE",
          "integrityImpact": "NONE",
          "accessComplexity": "LOW",
          "availabilityImpact": "NONE",
          "confidentialityImpact": "PARTIAL"
        },
        "acInsufInfo": false,
        "impactScore": 2.9,
        "baseSeverity": "MEDIUM",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 10,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": false
      }
    ]
  },
  "affected": [
    {
      "source": "cve@mitre.org",
      "affectedData": [
        {
          "vendor": "n/a",
          "product": "n/a",
          "versions": [
            {
              "status": "affected",
              "version": "n/a"
            }
          ]
        }
      ]
    }
  ],
  "published": "2015-09-22T15:59:00.107",
  "references": [
    {
      "url": "http://packetstormsecurity.com/files/133601/Pentaho-5.2.x-BA-Suite-PDI-Information-Disclosure.html",
      "tags": [
        "Exploit"
      ],
      "source": "cve@mitre.org"
    },
    {
      "url": "http://www.securityfocus.com/archive/1/536477/100/0/threaded",
      "source": "cve@mitre.org"
    },
    {
      "url": "https://support.pentaho.com/entries/78884125-Security-Vulnerability-Announcement-Feb-2015",
      "tags": [
        "Patch",
        "Vendor Advisory"
      ],
      "source": "cve@mitre.org"
    },
    {
      "url": "http://packetstormsecurity.com/files/133601/Pentaho-5.2.x-BA-Suite-PDI-Information-Disclosure.html",
      "tags": [
        "Exploit"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.securityfocus.com/archive/1/536477/100/0/threaded",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://support.pentaho.com/entries/78884125-Security-Vulnerability-Announcement-Feb-2015",
      "tags": [
        "Patch",
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-200"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "The GetResource servlet in Pentaho Business Analytics (BA) Suite 4.5.x, 4.8.x, and 5.0.x through 5.2.x and Pentaho Data Integration (PDI) Suite 4.3.x, 4.4.x, and 5.0.x through 5.2.x does not restrict access to files in the pentaho-solutions/system folder, which allows remote attackers to obtain passwords and other sensitive information via a file name in the resource parameter."
    },
    {
      "lang": "es",
      "value": "Vulnerabilidad en el servlet GetResource en Pentaho Business Analytics (BA) Suite 4.5.x, 4.8.x y 5.0.x hasta la versión 5.2.x y Pentaho Data Integration (PDI) Suite 4.3.x, 4.4.x, y 5.0.x hasta la versión 5.2.x, no restringe el acceso a los archivos en la carpeta pentaho-solutions/system, lo que permite a atacantes remotos obtener contraseñas y otra información sensible a través de un nombre de archivo en el parámetro resource."
    }
  ],
  "lastModified": "2026-06-17T00:31:38.810",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:pentaho:data_integration:4.3:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "8B2C1FC8-0787-4357-8B0A-125D2BF3418B"
            },
            {
              "criteria": "cpe:2.3:a:pentaho:data_integration:4.4:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "6C66215B-13D7-4B34-A33B-EDFB77E5D128"
            },
            {
              "criteria": "cpe:2.3:a:pentaho:data_integration:5.0:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "CBBE7301-81A0-41AB-9EFB-28791E6544AF"
            },
            {
              "criteria": "cpe:2.3:a:pentaho:data_integration:5.1:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "7246E3BC-3EB7-4AE6-B108-CB1B0786F275"
            },
            {
              "criteria": "cpe:2.3:a:pentaho:data_integration:5.2:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "66ADD153-3A7D-4D71-963F-EAA3FE0D4A4E"
            }
          ],
          "operator": "OR"
        }
      ]
    },
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:pentaho:business_analytics:4.5:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "FE9C6E6F-CE9C-4FDA-9405-E03B21EBA153"
            },
            {
              "criteria": "cpe:2.3:a:pentaho:business_analytics:4.8:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "BF618DEB-8AF9-4DB5-B03B-E69219EE020E"
            },
            {
              "criteria": "cpe:2.3:a:pentaho:business_analytics:5.0:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "C0E25BD3-540F-4722-B019-F2709D398536"
            },
            {
              "criteria": "cpe:2.3:a:pentaho:business_analytics:5.1:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "E6A6A70A-DDA1-41AF-8E24-2AE698813B69"
            },
            {
              "criteria": "cpe:2.3:a:pentaho:business_analytics:5.2:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "B1B3A812-E5E7-42E1-A107-2AEE2232A0FD"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "cve@mitre.org"
}