CVE-2021-45446

A vulnerability in Hitachi Vantara Pentaho Business Analytics Server versions before 9.2.0.2 and 8.3.0.25 does not cascade the hidden property to the children of the Home folder.  This directory listing provides an attacker with the complete index of all the resources located inside the directory.
References
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:hitachi:vantara_pentaho:*:*:*:*:*:*:*:*
cpe:2.3:a:hitachi:vantara_pentaho:*:*:*:*:*:*:*:*

History

No history.

Information

Published : 2022-11-02 15:15

Updated : 2023-11-07 03:39


NVD link : CVE-2021-45446

Mitre link : CVE-2021-45446

CVE.ORG link : CVE-2021-45446


JSON object : View

Products Affected

hitachi

  • vantara_pentaho
CWE
CWE-281

Improper Preservation of Permissions

CWE-548

Exposure of Information Through Directory Listing