Low severity2.7NVD Advisory· Published Nov 8, 2021· Updated Jun 17, 2026
CVE-2021-34685
CVE-2021-34685
Description
UploadService in Hitachi Vantara Pentaho Business Analytics through 9.1 does not properly verify uploaded user files, which allows an authenticated user to upload various files of different file types. Specifically, a .jsp file is not allowed, but a .jsp. file is allowed (and leads to remote code execution).
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3- Hitachi Vantara/Pentaho Business Analyticsdescription
- Range: <=9.1
Patches
Vulnerability mechanics
References
2- packetstormsecurity.com/files/164775/Pentaho-Business-Analytics-Pentaho-Business-Server-9.1-Filename-Bypass.htmlnvdExploitThird Party AdvisoryVDB Entry
- www.hitachi.com/hirt/security/index.htmlnvdVendor Advisory
News mentions
0No linked articles in our index yet.