Hitachi Vantara Pentaho Business Analytics Server versions before 9.4.0.1 and 9.3.0.2, including 8.3.x do not correctly protect the Post Analysis service endpoint of the data access plugin against out-of-band XML External Entity Reference.
Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2022-46911 | Hitachi Vantara Pentaho Business Analytics Server versions before 9.4.0.1 and 9.3.0.2, including 8.3.x do not correctly protect the Post Analysis service endpoint of the data access plugin against out-of-band XML External Entity Reference. |
Tue, 11 Feb 2025 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Status: PUBLISHED
Assigner: HITVAN
Published:
Updated: 2025-02-11T14:29:51.364Z
Reserved: 2022-10-26T21:25:26.142Z
Link: CVE-2022-43941
Updated: 2024-08-03T13:40:06.714Z
Status : Modified
Published: 2023-04-03T19:15:07.140
Modified: 2024-11-21T07:27:23.303
Link: CVE-2022-43941
No data.
OpenCVE Enrichment
No data.
EUVD