Showing 1 vulnerability on this page for vantara_pentaho

Signals CISA KEV Ransomware Nuclei
Hitachi vulnerability results
VulnerabilityTitle and contextCVSSEPSSPoCsSignalsSTIX action

hitachi vantara_pentaho Improper Authentication

An issue was discovered in Hitachi Vantara Pentaho through 9.1 and Pentaho Business Intelligence Server through 7.x. The Security Model has different layers of Access Control. One of these layers is the applicationContext security, which is defined in the applicationContext-spring-security.xml file. The default configuration allows an unauthenticated user with no previous knowledge of the platform settings to extract pieces of information without possessing valid credentials.

CWE-287CWE-863Nov 8, 20211 related artifact
CVSS5.3v3.1EPSS51.7%PoCs1SignalsNot listed in CISA KEVNo known ransomware use1 Nuclei templateSTIX