Hitachi Vantara Pentaho Business Analytics Server versions before 10.1.0.0 and 9.3.0.7, including 8.3.x do not correctly protect the ACL service endpoint of the Pentaho User Console against XML External Entity Reference.
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: HITVAN

Published: 2024-06-26T22:37:01.285Z

Updated: 2024-07-09T19:15:50.518Z

Reserved: 2024-03-13T19:18:14.913Z


Link: CVE-2024-28982

JSON object: View

cve-icon NVD Information

Status : Awaiting Analysis

Published: 2024-06-26T23:15:19.287

Modified: 2024-06-27T12:47:19.847


Link: CVE-2024-28982

JSON object: View

cve-icon Redhat Information

No data.

CWE