CVE Published: 03/04/2023 |
CVE Updated: 03/08/2024 |
CVE Year: 2022 Source: HITVAN |
Vendor: Hitachi Vantara |
Product: Pentaho Business Analytics Server Status : PUBLISHED
CVE-2022-43941 Description
Hitachi Vantara Pentaho Business Analytics Server versions before 9.4.0.1 and 9.3.0.2, including 8.3.x do not correctly protect the Post Analysis service endpoint of the data access plugin against out-of-band XML External Entity Reference.
Metrics
CVSS Version: 3.1 |
Base Score: 7.1 HIGH Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:L