4.3
CVE-2026-2255
- EPSS 0.17%
- Veröffentlicht 27.05.2026 02:51:31
- Zuletzt bearbeitet 24.07.2026 12:10:00
- CVE-Watchlists
- Unerledigt
Hitachi Vantara Pentaho Data Integration & Analytics - Insufficiently Protected Credentials
Hitachi Vantara Pentaho Data Integration & Analytics versions before 10.2.0.6 and 11.0.0.0, including 9.3.x and 8.3.x, expose Hadoop cluster credentials in plain text through the Cluster Test API. Although the user should not see those explicitly, the defect is mitigated by the fact the user can already leverage those credentials to submit jobs under the same account through the backend API.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Hitachi ≫ Vantara Pentaho Data Integration And Analytics Version < 10.2.0.7
Hitachi ≫ Vantara Pentaho Data Integration And Analytics Version > 10.2.0.8 < 11.0.0.0
Hitachi ≫ Vantara Pentaho Data Integration And Analytics Version8.3 Update-
Hitachi ≫ Vantara Pentaho Data Integration And Analytics Version9.3 Update-
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.17% | 0.06 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| security.vulnerabilities@hitachivantara.com | 4.3 | 2.8 | 1.4 |
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
|
CWE-522 Insufficiently Protected Credentials
The product transmits or stores authentication credentials, but it uses an insecure method that is susceptible to unauthorized interception and/or retrieval.
https://support.pentaho.com/hc/en-us/articles/45672235545101--Resolved-Hitachi-Vantara-Pentaho-Data-Integration-Analytics-Insufficiently-Protected-Credentials-Versions-before-10-2-0-6-and-11-0-0-0-Impacted-CVE-2026-2255