Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-26043 | Hitachi Vantara Pentaho Data Integration & Analytics versions before 10.1.0.0 and 9.3.0.8, including 8.3.x, discloses database passwords when searching metadata injectable fields. |
Thu, 12 Sep 2024 14:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 11 Sep 2024 23:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Hitachi Vantara Pentaho Data Integration & Analytics versions before 10.1.0.0 and 9.3.0.8, including 8.3.x, discloses database passwords when searching metadata injectable fields. | |
| Title | Hitachi Vantara Pentaho Data Integration & Analytics - Insufficiently Protected Credentials | |
| Weaknesses | CWE-522 | |
| References |
| |
| Metrics |
cvssV3_1
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: HITVAN
Published:
Updated: 2024-09-12T13:18:16.563Z
Reserved: 2024-03-13T19:18:14.912Z
Link: CVE-2024-28981
Updated: 2024-09-12T13:18:07.232Z
Status : Deferred
Published: 2024-09-12T00:15:02.127
Modified: 2026-04-15T00:35:42.020
Link: CVE-2024-28981
No data.
OpenCVE Enrichment
No data.
EUVD