CVE-2025-0758
Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
16/04/2025
Last modified:
17/04/2025
Description
Overview <br />
<br />
<br />
<br />
The product specifies permissions for a security-critical resource in a way that allows that resource to be read or modified by unintended actors. (CWE-732) <br />
<br />
<br />
<br />
Description <br />
<br />
<br />
<br />
Hitachi Vantara Pentaho Business Analytics Server prior to versions 10.2.0.2, including 9.3.x and 8.3.x, is installed with Karaf JMX beans enabled and accessible by default. <br />
<br />
<br />
<br />
Impact <br />
<br />
<br />
<br />
When the vulnerability is leveraged, a user with local execution privileges can access functionality exposed by Karaf beans contained in the product.
Impact
Base Score 3.x
6.10
Severity 3.x
MEDIUM