A vulnerability in Hitachi Vantara Pentaho Business Analytics Server versions before 9.2.0.2 and 8.3.0.25 does not cascade the hidden property to the children of the Home folder. This directory listing provides an attacker with the complete index of all the resources located inside the directory.
References
Link | Resource |
---|---|
https://support.pentaho.com/hc/en-us/articles/6744813983501 | Vendor Advisory |
Configurations
Configuration 1 (hide)
|
Information
Published : 2022-11-02 08:15
Updated : 2022-11-04 06:48
NVD link : CVE-2021-45446
Mitre link : CVE-2021-45446
JSON object : View
CWE
CWE-668
Exposure of Resource to Wrong Sphere
Products Affected
hitachi
- vantara_pentaho