目標達成 すべての支援者に感謝 — 100%達成しました!

目標: 1000 CNY · 調達済み: 1336 CNY

100%

CVE-2025-24909— Hitachi Vantara Pentaho Business Analytics Server 安全漏洞

CVSS 4.4 · Medium EPSS 0.28% · P21
新しい脆弱性情報の通知を購読するログインして購読

I. CVE-2025-24909の基本情報

脆弱性情報

脆弱性についてご質問がありますか?Shenlongの分析が参考になるかご確認ください!
Shenlongの10の質問を表示 ↗

高度な大規模言語モデル技術を使用していますが、出力には不正確または古い情報が含まれる可能性があります。Shenlongはデータの正確性を確保するよう努めていますが、実際の状況に基づいて検証・判断してください。

脆弱性タイトル
Hitachi Vantara Pentaho Business Analytics Server - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
ソース: CVE Program / CVE List V5
脆弱性説明
Overview   The software does not neutralize or incorrectly neutralize user-controllable input before it is placed in output that is used as a web page that is served to other users. (CWE-79)   Description   Hitachi Vantara Pentaho Business Analytics Server prior to versions 10.2.0.2, including 9.3.x and 8.3.x, allow a malicious URL to inject content into the Analyzer plugin interface.   Impact   Once the malicious script is injected, the attacker can perform a variety of malicious activities. The attacker could transfer private information, such as cookies that may include session information, from the victim's machine to the attacker. The attacker could send malicious requests to a web site on behalf of the victim, which could be especially dangerous to the site if the victim has administrator privileges to manage that site.
ソース: CVE Program / CVE List V5
CVSS情報
CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:N/I:H/A:N
ソース: CVE Program / CVE List V5
脆弱性タイプ
在Web页面生成时对输入的转义处理不恰当(跨站脚本)
ソース: CVE Program / CVE List V5
脆弱性タイトル
Hitachi Vantara Pentaho Business Analytics Server 安全漏洞
ソース: CNNVD (China National Vulnerability Database)
脆弱性説明
Hitachi Vantara Pentaho Business Analytics Server是日本日立制作所(Hitachi)公司的一个现代数据混合、集成和业务分析平台。 Hitachi Vantara Pentaho Business Analytics Server 10.2.0.2之前版本存在安全漏洞,该漏洞源于Analyzer插件接口未正确过滤用户输入,可能导致跨站脚本攻击。
ソース: CNNVD (China National Vulnerability Database)
CVSS情報
N/A
ソース: CNNVD (China National Vulnerability Database)
脆弱性タイプ
N/A
ソース: CNNVD (China National Vulnerability Database)

影響を受ける製品

ベンダープロダクト影響を受けるバージョンCPE購読
Hitachi VantaraPentaho Business Analytics Server 1.0 ~ 9.3.* -

II. CVE-2025-24909の公開POC

#POC説明ソースリンクShenlongリンク
AI生成POCプレミアム

公開POCは見つかりませんでした。

ログインしてAI POCを生成

III. CVE-2025-24909のインテリジェンス情報

登录查看更多情报信息。

CVE-2025-24909 其他参考 (1)

Same Patch Batch · Hitachi Vantara · 2025-04-16 · 8 CVEs total

CVE-2025-07569.1 CRITICALHitachi Vantara Pentaho Data Integration & Analytics - Improper Control of Resource Identi
CVE-2025-249086.8 MEDIUMHitachi Vantara Pentaho Data Integration & Analytics – Path Traversal
CVE-2025-249076.8 MEDIUMHitachi Vantara Pentaho Data Integration & Analytics – Path Traversal
CVE-2025-07586.1 MEDIUMHitachi Vantara Pentaho Business Analytics Server - Incorrect Permission Assignment for Cr
CVE-2025-249114.9 MEDIUMHitachi Vantara Pentaho Business Analytics Server - Improper Restriction of XML External E
CVE-2025-249104.9 MEDIUMHitachi Vantara Pentaho Business Analytics Server - Improper Restriction of XML External E
CVE-2025-07574.4 MEDIUMHitachi Vantara Pentaho Business Analytics Server - Improper Neutralization of Input Durin

IV. 関連脆弱性

V. CVE-2025-24909へのコメント

まだコメントはありません


コメントを残す