Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2797▼ 203 respecto a la semana anterior
Críticas / altas1352▲ 28 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)255▼ 266 respecto a la semana anterior
–

15 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaMedia (4.3)0.17%—Hitachi Vantara Pentaho Data Integration AND Analytics27/5/202624/7/2026
Hitachi Vantara Pentaho Data Integration & Analytics versions before 10.2.0.6 and 11.0.0.0, including 9.3.x and 8.3.x, expose Hadoop cluster credentials in plain text through the Cluster Test API. Although the user should not see those explicitly, the defect is mitigated by the fact the user can already leverage those…
AnalizadaMedia (6.3)0.15%—Hitachi Vantara Pentaho Data Integration AND Analytics27/5/202624/7/2026
Hitachi Vantara Pentaho Data Integration & Analytics versions before 10.2.0.6 and 11.0.0.0, including 9.3.x and 8.3.x, does not apply ACLs on certain API endpoints related to platform mail notfications.
AnalizadaAlta (7.7)0.20%—Hitachi Vantara Pentaho Data Integration AND Analytics27/5/202624/7/2026
Hitachi Vantara Pentaho Data Integration & Analytics versions before 10.2.0.7 and 11.0.0.0, including 9.3.x and 8.3.x, does not prevent certain XML parsers from resolving external entities.
AnalizadaAlta (7.2)0.34%—Hitachi Vantara Pentaho Data Integration AND Analytics13/5/202630/9/2026
Hitachi Vantara Pentaho Data Integration & Analytics of all versions contain a JDBC driver for H2 databases which is vulnerable to external script execution when a new connection is created by a data source administrator.
AnalizadaCrítica (9.1)0.39%—Hitachi Vantara Pentaho Data Integration AND Analytics10/3/202617/6/2026
Hitachi Vantara Pentaho Data Integration & Analytics versions before 10.2.0.6, including 9.3.x and 8.3.x, do not restrict Groovy scripts in new PRPT reports published by users, allowing insertion of arbitrary scripts and leading to a RCE.
AplazadaMedia (5.3)0.29%—Hitachivantara Pentaho Data IntegrationAIHitachivantara Pentaho Analytics Community Dashboard FrameworkAI15/12/202517/6/2026
Hitachi Vantara Pentaho Data Integration and Analytics Community Dashboard Framework prior to versions 10.2.0.4, including 9.3.0.x and 8.3.x display the full server stack trace when encountering an error within the GetCdfResource servlet.
AplazadaMedia (4.9)0.42%—Hitachivantara Pentaho Business Analytics ServerAIHitachivantara Pentaho Data IntegrationAI16/4/202517/6/2026
Overview XML documents optionally contain a Document Type Definition (DTD), which, among other features, enables the definition of XML entities. It is possible to define an entity by providing a substitution string in the form of a URI. Once the content of the URI is read, it is fed back into the application that is…
AplazadaMedia (6.8)0.49%—Hitachivantara Pentaho Data Integration AND AnalyticsAI16/4/202517/6/2026
Overview The product uses external input to construct a pathname that should be within a restricted directory, but it does not properly neutralize '.../...//' (doubled triple dot slash) sequences that can resolve to a location that is outside of that directory. (CWE-35) Description Hitachi Vantara Pentaho Data…
AplazadaMedia (6.8)0.43%—Hitachivantara Pentaho Data IntegrationAI16/4/202517/6/2026
Overview The product uses external input to construct a pathname that should be within a restricted directory, but it does not properly neutralize '.../...//' (doubled triple dot slash) sequences that can resolve to a location that is outside of that directory. (CWE-35) Description Hitachi Vantara Pentaho Data…
AplazadaCrítica (9.1)0.94%—Hitachivantara Pentaho Data Integration AND AnalyticsAI16/4/202517/6/2026
Overview The product receives input from an upstream component, but it does not restrict or incorrectly restricts the input before it is used as an identifier for a resource that may be outside the intended sphere of control. (CWE-99) Description Hitachi Vantara Pentaho Data Integration & Analytics versions before…
AplazadaMedia (6.3)0.29%—Hitachivantara Pentaho Data Integration AND AnalyticsAI20/2/202517/6/2026
The product transmits or stores authentication credentials, but it uses an insecure method that is susceptible to unauthorized interception and/or retrieval. (CWE-522) Hitachi Vantara Pentaho Data Integration & Analytics versions before 10.2.0.0 and 9.3.0.8, including 8.3.x, discloses database passwords when saving…
AplazadaAlta (8.8)0.72%—Hitachivantara Pentaho Data Integration AND AnalyticsAI19/2/202517/6/2026
The product receives input from an upstream component, but it does not restrict or incorrectly restricts the input before it is used as an identifier for a resource that may be outside the intended sphere of control. (CWE-99) Hitachi Vantara Pentaho Data Integration & Analytics versions before 10.2.0.0 and 9.3.0.9,…
AplazadaAlta (8.5)0.27%—Hitachivantara Pentaho Data IntegrationAIHitachivantara Pentaho AnalyticsAI12/9/202417/6/2026
Hitachi Vantara Pentaho Data Integration & Analytics versions before 10.1.0.0 and 9.3.0.8, including 8.3.x, discloses database passwords when searching metadata injectable fields.
AnalizadaMedia (5.3)0.38%—Hitachi Vantara Pentaho Data Integration AND Analytics28/2/202417/6/2026
Hitachi Vantara Pentaho Data Integration & Analytics versions before 10.1.0.0 and 9.3.0.6, including 9.5.x and 8.3.x, display the version of Tomcat when a server error is encountered.
ModificadaAlta (8.8)0.64%—Hitachi Pentaho Data Integration AND Analytics12/12/202317/6/2026
Hitachi Vantara Pentaho Data Integration & Analytics versions before 9.5.0.1 and 9.3.0.5, including 8.3.x does not restrict JNDI identifiers during the creation of XActions, allowing control of system level data sources.