Hitachivantara
Hitachivantara Pentaho Business Analytics Server: vulnerabilidades y CVE
Hitachivantara Pentaho Business Analytics Server tiene 12 vulnerabilidades publicadas, 0 de ellas en los últimos 12 meses. 1 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE12
Últimos 12 meses0
Críticas1
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2025-24911 | Media (4.9) | 0.44% | — | 16 abr 2025 | Overview XML documents optionally contain a Document Type Definition (DTD), which, among other features, enables the definition of XML entities. It is possible to define an entity by providing a substitution string in… |
| CVE-2025-24910 | Media (4.9) | 0.42% | — | 16 abr 2025 | Overview XML documents optionally contain a Document Type Definition (DTD), which, among other features, enables the definition of XML entities. It is possible to define an entity by providing a substitution string in… |
| CVE-2025-24909 | Media (4.4) | 0.29% | — | 16 abr 2025 | Overview The software does not neutralize or incorrectly neutralize user-controllable input before it is placed in output that is used as a web page that is served to other users. (CWE-79) Description Hitachi Vantara… |
| CVE-2025-0758 | Media (6.1) | 0.15% | — | 16 abr 2025 | Overview The product specifies permissions for a security-critical resource in a way that allows that resource to be read or modified by unintended actors. (CWE-732) Description Hitachi Vantara Pentaho Business… |
| CVE-2025-0757 | Media (4.4) | 0.29% | — | 16 abr 2025 | Overview The software does not neutralize or incorrectly neutralize user-controllable input before it is placed in output that is used as a web page that is served to other users. (CWE-79) Description Hitachi Vantara… |
| CVE-2024-6697 | Media (6.5) | 0.33% | — | 20 feb 2025 | The product does not handle or incorrectly handles when it has insufficient privileges to access resources or functionality as specified by their permissions. This may cause it to follow unexpected code paths that may… |
| CVE-2024-6696 | Media (4.9) | 0.37% | — | 20 feb 2025 | The product implements access controls via a policy or other feature with the intention to disable or restrict accesses (reads and/or writes) to assets in a system from untrusted agents. However, implemented access… |
| CVE-2024-37363 | Media (6.5) | 0.33% | — | 20 feb 2025 | The product does not perform an authorization check when an actor attempts to access a resource or perform an action. (CWE-862) Hitachi Vantara Pentaho Business Analytics Server versions before 10.2.0.0 and 9.3.0.8,… |
| CVE-2024-37361 | Crítica (9.9) | 0.52% | — | 20 feb 2025 | The application deserializes untrusted data without sufficiently verifying that the resulting data will be valid. (CWE-502) Hitachi Vantara Pentaho Business Analytics Server versions before 10.2.0.0 and 9.3.0.9,… |
| CVE-2024-5705 | Alta (8.8) | 0.49% | — | 19 feb 2025 | The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check. This allows attackers to bypass intended access restrictions.… |
| CVE-2024-37360 | Media (4.4) | 0.28% | — | 19 feb 2025 | Hitachi Vantara Pentaho Business Analytics Server - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') The software does not neutralize or incorrectly neutralize user-controllable input… |
| CVE-2024-37359 | Alta (8.6) | 0.52% | — | 19 feb 2025 | The web server receives a URL or similar request from an upstream component and retrieves the contents of this URL, but it does not sufficiently ensure that the request is being sent to the expected destination.… |
🎯 Cómo se explota (técnicas ATT&CK)
Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.