Description
Hitachi Vantara Pentaho Data Integration & Analytics versions before 9.5.0.1 and 9.3.0.5, including
8.3.x does not restrict JNDI identifiers during the creation of XActions, allowing control of system level data sources.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2023-44175 | Hitachi Vantara Pentaho Data Integration & Analytics versions before 9.5.0.1 and 9.3.0.5, including 8.3.x does not restrict JNDI identifiers during the creation of XActions, allowing control of system level data sources. |
References
| Link | Providers |
|---|---|
| https://support.pentaho.com/hc/en-us/articles/19668665099533 |
|
History
No history.
Status: PUBLISHED
Assigner: HITVAN
Published:
Updated: 2024-08-02T06:55:03.685Z
Reserved: 2023-07-05T16:19:15.295Z
Link: CVE-2023-3517
No data.
Status : Modified
Published: 2023-12-12T23:15:07.003
Modified: 2024-11-21T08:17:26.280
Link: CVE-2023-3517
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD