« Volver al listado

CVE-2024-37360

Estado: AplazadaMedia (4.4)—

Hitachi Vantara Pentaho Business Analytics Server - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

The software does not neutralize or incorrectly neutralize user-controllable input before it is placed in output that is used as a web page that is served to other users. (CWE-79)

Hitachi Vantara Pentaho Business Analytics Server prior to versions 10.2.0.0 and 9.3.0.9, including 8.3.x, allow a malicious URL to inject content into the Analyzer plugin interface.

Once the malicious script is injected, the attacker can perform a variety of malicious activities.

Leer descripción completaMostrar menos

The attacker could transfer private information, such as cookies that may include session information, from the victim's machine to the attacker. The attacker could send malicious requests to a web site on behalf of the victim, which could be especially dangerous to the site if the victim has administrator privileges to manage that site.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2024-37360",
  "cveTags": [],
  "metrics": {
    "ssvcV203": [
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "ssvcData": {
          "id": "CVE-2024-37360",
          "role": "CISA Coordinator",
          "options": [
            {
              "exploitation": "none"
            },
            {
              "automatable": "no"
            },
            {
              "technicalImpact": "partial"
            }
          ],
          "version": "2.0.3",
          "timestamp": "2025-02-20T17:21:56.788347Z"
        }
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Secondary",
        "source": "security.vulnerabilities@hitachivantara.com",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 4.4,
          "attackVector": "NETWORK",
          "baseSeverity": "MEDIUM",
          "vectorString": "CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:N/I:H/A:N",
          "integrityImpact": "HIGH",
          "userInteraction": "NONE",
          "attackComplexity": "HIGH",
          "availabilityImpact": "NONE",
          "privilegesRequired": "HIGH",
          "confidentialityImpact": "NONE"
        },
        "impactScore": 3.6,
        "exploitabilityScore": 0.7
      }
    ]
  },
  "affected": [
    {
      "source": "security.vulnerabilities@hitachivantara.com",
      "affectedData": [
        {
          "vendor": "Hitachi Vantara",
          "product": "Pentaho Data Integration & Analytics",
          "versions": [
            {
              "status": "affected",
              "version": "10.0",
              "lessThan": "10.2.0.0",
              "versionType": "maven"
            }
          ],
          "defaultStatus": "unaffected"
        },
        {
          "vendor": "Hitachi Vantara",
          "product": "Pentaho Business Analytics Server",
          "versions": [
            {
              "status": "affected",
              "version": "1.0",
              "lessThan": "9.3.0.9",
              "versionType": "maven"
            }
          ],
          "defaultStatus": "unaffected"
        }
      ]
    }
  ],
  "published": "2025-02-19T23:15:10.537",
  "references": [
    {
      "url": "https://support.pentaho.com/hc/en-us/articles/34298351866893--Resolved-Hitachi-Vantara-Pentaho-Business-Analytics-Server-Improper-Neutralization-of-Input-During-Web-Page-Generation-Cross-site-Scripting-CVE-2024-37360",
      "source": "security.vulnerabilities@hitachivantara.com"
    }
  ],
  "vulnStatus": "Deferred",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "security.vulnerabilities@hitachivantara.com",
      "description": [
        {
          "lang": "en",
          "value": "CWE-79"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "Hitachi Vantara Pentaho Business Analytics Server - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') \n\n\n\n \n\n\n\nThe software does not neutralize or incorrectly neutralize user-controllable input before it is placed in output that is used as a web page that is served to other users. (CWE-79)\n\n\n\n \n\n\n\nHitachi Vantara Pentaho Business Analytics Server prior to versions 10.2.0.0 and 9.3.0.9, including 8.3.x, allow a malicious URL to inject content into the Analyzer plugin interface.\n\n\n\n \n\n\n\n\nOnce the malicious script is injected, the attacker can perform a variety of malicious activities. The attacker could transfer private information, such as cookies that may include session information, from the victim's machine to the attacker. The attacker could send malicious requests to a web site on behalf of the victim, which could be especially dangerous to the site if the victim has administrator privileges to manage that site."
    },
    {
      "lang": "es",
      "value": "Hitachi Vantara Pentaho Business Analytics Server - Neutralización incorrecta de la entrada durante la generación de páginas web ('Cross-site Scripting') El software no neutraliza o neutraliza incorrectamente la entrada controlable por el usuario antes de colocarla en la salida que se utiliza como una página web que se ofrece a otros usuarios. (CWE-79) Hitachi Vantara Pentaho Business Analytics Server anterior a las versiones 10.2.0.0 y 9.3.0.9, incluida la 8.3.x, permite que una URL maliciosa inyecte contenido en la interfaz del complemento Analyzer. Una vez que se inyecta el script malicioso, el atacante puede realizar una variedad de actividades maliciosas. El atacante podría transferir información privada, como cookies que pueden incluir información de sesión, desde la máquina de la víctima al atacante. El atacante podría enviar solicitudes maliciosas a un sitio web en nombre de la víctima, lo que podría ser especialmente peligroso para el sitio si la víctima tiene privilegios de administrador para administrar ese sitio."
    }
  ],
  "lastModified": "2026-06-17T07:38:13.237",
  "sourceIdentifier": "security.vulnerabilities@hitachivantara.com"
}