CVE-2024-6696 – Here are the titles: 1. Hitachi Vantara Pentaho Business Analytics Server Access Control Bypass 2. Hitachi Vantara Pentaho Business Analytics Server Authorization Check Failure

The following table lists the changes that have been made to the CVE-2024-6696 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. New CVE Received by [email protected] Feb. 20, 2025 Action […]

CVE-2024-37363 – Hitachi Vantara Pentaho Business Analytics Server Authorization Bypass

The following table lists the changes that have been made to the CVE-2024-37363 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. New CVE Received by [email protected] Feb. 20, 2025 Action […]

CVE-2024-37362 – Hitachi Vantara Pentaho Data Integration & Analytics Database Password Disclosure

The following table lists the changes that have been made to the CVE-2024-37362 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. New CVE Received by [email protected] Feb. 20, 2025 Action […]

CVE-2024-37361 – Hitachi Vantara Pentaho Business Analytics Server JSON Deserialization Vulnerability (CWE-502)

The application deserializes untrusted data without sufficiently verifying that the resulting data will be valid. (CWE-502)   Hitachi Vantara Pentaho Business Analytics Server versions before 10.2.0.0 and 9.3.0.9, including 8.3.x, deserialize untrusted JSON data without constraining the parser to approved classes and methods.   When developers place no restrictions on “gadget chains,” or series of […]

CVE-2024-12284 – Citrix NetScaler Console and Agent Authenticated Privilege Escalation

The following table lists the changes that have been made to the CVE-2024-12284 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. New CVE Received by [email protected] Feb. 20, 2025 Action […]