CVE-2024-37363 – Hitachi Vantara Pentaho Business Analytics Server Authorization Bypass

The following table lists the changes that have been made to the
CVE-2024-37363 vulnerability over time.

Vulnerability history details can be useful for understanding the evolution
of a vulnerability, and for identifying the most recent changes that may
impact the vulnerability’s severity, exploitability, or other characteristics.

  • New CVE Received
    by [email protected]

    Feb. 20, 2025

    Action Type Old Value New Value
    Added Description The product does not perform an authorization check when an actor attempts to access a resource or perform an action. (CWE-862)

     Hitachi Vantara Pentaho Business Analytics Server versions before 10.2.0.0 and 9.3.0.8, including 8.3.x, do not correctly perform an authorization check in the data source management service.

    When access control checks are incorrectly applied, users can access data or perform actions that they should not be allowed to perform. This can lead to a wide range of problems, including information exposures and denial of service.

    Added CVSS V3.1 AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
    Added CWE CWE-862
    Added Reference https://support.pentaho.com/hc/en-us/articles/34296230504589–Resolved-Hitachi-Vantara-Pentaho-Business-Analytics-Server-Incorrect-Authorization-Versions-before-10-2-0-0-and-9-3-0-8-including-8-3-x-Impacted-CVE-2024-37363
Share the Post:

Related Posts