CVE Published: 02/11/2022 |
CVE Updated: 04/08/2024 |
CVE Year: 2021 Source: HITVAN |
Vendor: Hitachi Vantara |
Product: Pentaho Business Analytics Server Status : PUBLISHED
CVE-2021-45446 Description
A vulnerability in
Hitachi Vantara Pentaho Business Analytics Server versions before 9.2.0.2 and
8.3.0.25 does not cascade the hidden property to the children of the Home folder. This directory listing provides an attacker with the complete index of all the resources located
inside the directory.
Metrics
CVSS Version: 3.1 |
Base Score: 5 MEDIUM Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:N/A:N
Common Attack Pattern Enumeration and Classification (CAPEC)
CAPEC-ID: CAPEC Description: A directory listing provides an attacker with the complete index of all the resources located inside of the directory. The specific risks and consequences vary depending on which files are listed and accessible.