CVE-2025-0758 – Hitachi Vantara Pentaho Business Analytics Server JMX Bean Privilege Escalation

The following table lists the changes that have been made to the
CVE-2025-0758 vulnerability over time.

Vulnerability history details can be useful for understanding the evolution
of a vulnerability, and for identifying the most recent changes that may
impact the vulnerability’s severity, exploitability, or other characteristics.

  • New CVE Received
    by [email protected]

    Apr. 16, 2025

    Action Type Old Value New Value
    Added Description Overview 

    The product specifies permissions for a security-critical resource in a way that allows that resource to be read or modified by unintended actors. (CWE-732) 

    Description 

    Hitachi Vantara Pentaho Business Analytics Server prior to versions 10.2.0.2, including 9.3.x and 8.3.x, is installed with Karaf JMX beans enabled and accessible by default. 

    Impact 

    When the vulnerability is leveraged, a user with local execution privileges can access functionality exposed by Karaf beans contained in the product.

    Added CVSS V3.1 AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:H
    Added CWE CWE-732
    Added Reference https://support.pentaho.com/hc/en-us/articles/35781318194061–Resolved-Hitachi-Vantara-Pentaho-Business-Analytics-Server-Incorrect-Permission-Assignment-for-Critical-Resource-Versions-before-10-2-0-2-including-9-3-x-Impacted-CVE-2025-0758
Share the Post:

Related Posts