A vulnerability in Hitachi Vantara Pentaho Business Analytics Server versions before 9.2.0.2 and 8.3.0.25 does not cascade the hidden property to the children of the Home folder.  This directory listing provides an attacker with the complete index of all the resources located inside the directory.
History

Fri, 02 May 2025 16:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


cve-icon MITRE

Status: PUBLISHED

Assigner: HITVAN

Published: 2022-11-02T14:26:02.105Z

Updated: 2025-05-02T15:52:28.178Z

Reserved: 2021-12-21T05:57:40.703Z

Link: CVE-2021-45446

cve-icon Vulnrichment

Updated: 2024-08-04T04:39:20.999Z

cve-icon NVD

Status : Modified

Published: 2022-11-02T15:15:09.683

Modified: 2024-11-21T06:32:13.470

Link: CVE-2021-45446

cve-icon Redhat

No data.