VYPR
Unrated severityNVD Advisory· Published Jun 26, 2024· Updated Sep 11, 2024

Hitachi Vantara Pentaho Business Analytics Server - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

CVE-2024-28983

Description

Hitachi Vantara Pentaho Business Analytics Server prior to versions 10.1.0.0 and 9.3.0.7, including 8.3.x allow a malicious URL to inject content into the Analyzer plugin interface.

Affected products

2
  • <10.1.0.0 && <9.3.0.7, includes 8.3.x+ 1 more
    • (no CPE)range: <10.1.0.0 && <9.3.0.7, includes 8.3.x
    • (no CPE)range: 1.0

Patches

Vulnerability mechanics

References

1

News mentions

0

No linked articles in our index yet.