Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2970▼ 106 respecto a la semana anterior
Críticas / altas1447▲ 86 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
29 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (4.9) | 0.44% | — | Hitachivantara Pentaho Business Analytics ServerAI | 16/4/2025 | 17/6/2026 | Overview XML documents optionally contain a Document Type Definition (DTD), which, among other features, enables the definition of XML entities. It is possible to define an entity by providing a substitution string in the form of a URI. Once the content of the URI is read, it is fed back into the application that is… | |
| Aplazada | Media (4.9) | 0.42% | — | Hitachivantara Pentaho Business Analytics ServerAIHitachivantara Pentaho Data IntegrationAI | 16/4/2025 | 17/6/2026 | Overview XML documents optionally contain a Document Type Definition (DTD), which, among other features, enables the definition of XML entities. It is possible to define an entity by providing a substitution string in the form of a URI. Once the content of the URI is read, it is fed back into the application that is… | |
| Aplazada | Media (4.4) | 0.29% | — | Hitachivantara Pentaho Business Analytics ServerAI | 16/4/2025 | 17/6/2026 | Overview The software does not neutralize or incorrectly neutralize user-controllable input before it is placed in output that is used as a web page that is served to other users. (CWE-79) Description Hitachi Vantara Pentaho Business Analytics Server prior to versions 10.2.0.2, including 9.3.x and 8.3.x, allow a… | |
| Aplazada | Media (6.1) | 0.15% | — | Hitachivantara Pentaho Business Analytics ServerAI | 16/4/2025 | 17/6/2026 | Overview The product specifies permissions for a security-critical resource in a way that allows that resource to be read or modified by unintended actors. (CWE-732) Description Hitachi Vantara Pentaho Business Analytics Server prior to versions 10.2.0.2, including 9.3.x and 8.3.x, is installed with Karaf JMX beans… | |
| Aplazada | Media (4.4) | 0.29% | — | Hitachivantara Pentaho Business Analytics ServerAI | 16/4/2025 | 17/6/2026 | Overview The software does not neutralize or incorrectly neutralize user-controllable input before it is placed in output that is used as a web page that is served to other users. (CWE-79) Description Hitachi Vantara Pentaho Business Analytics Server prior to versions 10.2.0.2, including 9.3.x and 8.3.x, allow a… | |
| Aplazada | Media (6.5) | 0.33% | — | Hitachivantara Pentaho Business Analytics ServerAI | 20/2/2025 | 17/6/2026 | The product does not handle or incorrectly handles when it has insufficient privileges to access resources or functionality as specified by their permissions. This may cause it to follow unexpected code paths that may leave the product in an invalid state. (CWE-280) Hitachi Vantara Pentaho Business Analytics Server… | |
| Aplazada | Media (4.9) | 0.37% | — | Hitachivantara Pentaho Business Analytics ServerAI | 20/2/2025 | 17/6/2026 | The product implements access controls via a policy or other feature with the intention to disable or restrict accesses (reads and/or writes) to assets in a system from untrusted agents. However, implemented access controls lack required granularity, which renders the control policy too broad because it allows… | |
| Aplazada | Media (6.5) | 0.33% | — | Hitachivantara Pentaho Business Analytics ServerAI | 20/2/2025 | 17/6/2026 | The product does not perform an authorization check when an actor attempts to access a resource or perform an action. (CWE-862) Hitachi Vantara Pentaho Business Analytics Server versions before 10.2.0.0 and 9.3.0.8, including 8.3.x, do not correctly perform an authorization check in the data source management service.… | |
| Aplazada | Crítica (9.9) | 0.52% | — | Hitachivantara Pentaho Business Analytics ServerAI | 20/2/2025 | 17/6/2026 | The application deserializes untrusted data without sufficiently verifying that the resulting data will be valid. (CWE-502) Hitachi Vantara Pentaho Business Analytics Server versions before 10.2.0.0 and 9.3.0.9, including 8.3.x, deserialize untrusted JSON data without constraining the parser to approved classes and… | |
| Aplazada | Alta (8.8) | 0.49% | — | Hitachivantara Pentaho Business Analytics ServerAI | 19/2/2025 | 17/6/2026 | The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check. This allows attackers to bypass intended access restrictions. (CWE-863) Hitachi Vantara Pentaho Business Analytics Server versions before 10.2.0.0 and 9.3.0.9,… | |
| Aplazada | Media (4.4) | 0.28% | — | Hitachivantara Pentaho Business Analytics ServerAI | 19/2/2025 | 17/6/2026 | Hitachi Vantara Pentaho Business Analytics Server - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') The software does not neutralize or incorrectly neutralize user-controllable input before it is placed in output that is used as a web page that is served to other users. (CWE-79)… | |
| Aplazada | Alta (8.6) | 0.52% | — | Hitachivantara Pentaho Business Analytics ServerAI | 19/2/2025 | 17/6/2026 | The web server receives a URL or similar request from an upstream component and retrieves the contents of this URL, but it does not sufficiently ensure that the request is being sent to the expected destination. (CWE-918) Hitachi Vantara Pentaho Business Analytics Server versions before 10.2.0.0 and 9.3.0.9, including… | |
| Modificada | Media (6.1) | 0.25% | — | Hitachi Pentaho Business Analytics Server | 26/6/2024 | 17/6/2026 | Hitachi Vantara Pentaho Business Analytics Server prior to versions 10.1.0.0 and 9.3.0.7, including 8.3.x allow a malicious URL to inject content into the Analyzer plugin interface. | |
| Analizada | Media (6.1) | 0.29% | — | Hitachi Pentaho Business Analytics Server | 26/6/2024 | 17/6/2026 | Hitachi Vantara Pentaho Business Analytics Server prior to versions 10.1.0.0 and 9.3.0.7, including 8.3.x allow a malicious URL to inject content into the Analyzer plugin interface. | |
| Modificada | Alta (8.2) | 0.38% | — | Hitachi Pentaho Business Analytics Server | 26/6/2024 | 17/6/2026 | Hitachi Vantara Pentaho Business Analytics Server versions before 10.1.0.0 and 9.3.0.7, including 8.3.x do not correctly protect the ACL service endpoint of the Pentaho User Console against XML External Entity Reference. | |
| Modificada | Media (4.3) | 0.38% | — | Hitachi Vantara PentahoHitachi Vantara Pentaho Business Analytics Server | 24/5/2023 | 17/6/2026 | Hitachi Vantara Pentaho Business Analytics Server versions before 9.4.0.1 and 9.3.0.3, including 8.3.x expose dashboard prompts to users who are not part of the authorization list. | |
| Modificada | Alta (8.8) | 0.63% | — | Hitachi Vantara PentahoHitachi Vantara Pentaho Business Analytics Server | 24/5/2023 | 17/6/2026 | Hitachi Vantara Pentaho Business Analytics Server versions before 9.4.0.1 and 9.3.0.3, including 8.3.x deserialize untrusted JSON data without constraining the parser to approved classes and methods. | |
| Modificada | Media (6.1) | 0.35% | — | Hitachi Vantara Pentaho Business Analytics Server | 3/4/2023 | 17/6/2026 | Hitachi Vantara Pentaho Business Analytics Server prior to versions 9.4.0.1 and 9.3.0.2, including 8.3.x allow a malicious URL to inject content into the Pentaho User Console through session variables. | |
| Modificada | Media (4.3) | 0.43% | — | Hitachi Vantara Pentaho Business Analytics Server | 3/4/2023 | 17/6/2026 | Hitachi Vantara Pentaho Business Analytics Server prior to versions 9.4.0.0 and 9.3.0.2, including 8.3.x display the full parametrized SQL query in an error message when an invalid character is used within a Pentaho Report (*.prpt). | |
| Modificada | Media (4.3) | 0.43% | — | Hitachi Vantara Pentaho Business Analytics Server | 3/4/2023 | 17/6/2026 | Hitachi Vantara Pentaho Business Analytics Server prior to versions 9.4.0.0 and 9.3.0.2, including 8.3.x display the target path on host when a file is uploaded with an invalid character in its name. | |
| Modificada | Media (6.5) | 0.53% | — | Hitachi Vantara Pentaho Business Analytics Server | 3/4/2023 | 17/6/2026 | Hitachi Vantara Pentaho Business Analytics Server versions before 9.4.0.1 and 9.3.0.2, including 8.3.x do not correctly protect the Post Analysis service endpoint of the data access plugin against out-of-band XML External Entity Reference. | |
| Modificada | Alta (8.8) | 0.56% | — | Hitachi Vantara Pentaho Business Analytics Server | 3/4/2023 | 17/6/2026 | Hitachi Vantara Pentaho Business Analytics Server versions before 9.4.0.1 and 9.3.0.2, including 8.3.x do not correctly perform an authorization check in the data source management service. | |
| Analizada | Crítica (9.8) | 92% | ⚠ Explotación activa💥 Exploit | Hitachi Vantara Pentaho Business Analytics Server | 3/4/2023 | 17/6/2026 | Hitachi Vantara Pentaho Business Analytics Server versions before 9.4.0.1 and 9.3.0.2, including 8.3.x contain security restrictions using non-canonical URLs which can be circumvented. | |
| Modificada | Alta (8.8) | 26% | — | Hitachi Vantara Pentaho Business Analytics Server | 3/4/2023 | 17/6/2026 | Hitachi Vantara Pentaho Business Analytics Server prior to versions 9.4.0.1 and 9.3.0.2, including 8.3.x cannot allow a system administrator to disable scripting capabilities of Pentaho Reports (*.prpt) through the JVM script manager. | |
| Modificada | Media (6.5) | 0.39% | — | Hitachi Vantara Pentaho Business Analytics Server | 3/4/2023 | 17/6/2026 | Hitachi Vantara Pentaho Business Analytics Server versions before 9.4.0.0 and 9.3.0.1, including 8.3.x with the Big Data Plugin expose the username and password of clusters in clear text into system logs. |