CVE-2021-34684

CRITICAL

Hitachi Vantara Pentaho < 9.1.0.0 - Unauthenticated SQL Injection via Dashboard Editor API

Title source: llm
STIX 2.1

Description

Hitachi Vantara Pentaho Business Analytics through 9.1 allows an unauthenticated user to execute arbitrary SQL queries on any Pentaho data source and thus retrieve data from the related databases, as demonstrated by an api/repos/dashboards/editor URI.

References (2)

Core 2
Core References
Vendor Advisory x_refsource_misc
https://www.hitachi.com/hirt/security/index.html

Scores

CVSS v3 9.8
EPSS 0.2633
EPSS Percentile 96.4%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-89
Status published
Products (1)
hitachi/vantara_pentaho < 9.1.0.0
Published Nov 08, 2021
Tracked Since Feb 18, 2026