CVE-2024-37363
Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
20/02/2025
Last modified:
20/02/2025
Description
The product does not perform an authorization check when an actor attempts to access a resource or perform an action. (CWE-862)<br />
<br />
<br />
<br />
<br />
<br />
<br />
Hitachi Vantara Pentaho Business Analytics Server versions before 10.2.0.0 and 9.3.0.8, including 8.3.x, do not correctly perform an authorization check in the data source management service.<br />
<br />
<br />
<br />
<br />
<br />
<br />
<br />
<br />
When access control checks are incorrectly applied, users can access data or perform actions that they should not be allowed to perform. This can lead to a wide range of problems, including information exposures and denial of service.
Impact
Base Score 3.x
6.50
Severity 3.x
MEDIUM



