Hitachi Vantara Pentaho Business Analytics Server - Improper Restriction of XML External Entity Reference
Description
Hitachi Vantara Pentaho Business Analytics Server versions before 9.4.0.1 and 9.3.0.2, including 8.3.x do not correctly protect the Post Analysis service endpoint of the data access plugin against out-of-band XML External Entity Reference.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Hitachi Vantara Pentaho BA Server before 9.4.0.1 and 9.3.0.2 fails to protect the Post Analysis service endpoint against out-of-band XML external entity (XXE) attacks.
Vulnerability
Hitachi Vantara Pentaho Business Analytics Server versions before 9.4.0.1 and 9.3.0.2, including all 8.3.x releases, do not correctly protect the Post Analysis service endpoint of the data access plugin against out-of-band XML External Entity Reference (XXE) attacks [1]. The flaw exists because the endpoint processes XML documents that may contain a Document Type Definition (DTD) allowing external entity definitions without proper restrictions.
Exploitation
An authenticated attacker can submit a crafted XML file to the vulnerable Post Analysis service endpoint [1]. The XML file defines an external entity using a URI with schemes such as file:// or http://. The server then processes the entity and may echo the retrieved data back in an error message or other response. No additional privileges beyond standard authentication are required; the attacker only needs network access to the affected service.
Impact
Successful exploitation allows an attacker to read arbitrary local files from the server (e.g., via file:// URI), potentially exposing sensitive configuration or data. Using http:// or other URI schemes, the attacker can force the server to make outgoing requests to internal or external hosts, enabling port scanning or other reconnaissance from the server's network position [1]. This constitutes information disclosure and can be used to bypass firewalls or hide the attack source.
Mitigation
As a workaround, the data access plugin can be removed from the software installation to mitigate the defect. The vendor recommends upgrading to Hitachi Vantara Pentaho Business Analytics Server version 9.3.0.2 (Long Term Support) or 9.4.0.1 or newer [1]. The fix is included in those releases. No information about CVE listing in CISA KEV is provided in the references.
AI Insight generated on May 25, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected products
2- Range: <9.4.0.1 and <9.3.0.2, including 8.3.x
- Range: 1.0
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
1News mentions
0No linked articles in our index yet.