CVE-2021-34685
- EPSS 1.97%
- Veröffentlicht 08.11.2021 04:15:08
- Zuletzt bearbeitet 21.11.2024 06:10:56
UploadService in Hitachi Vantara Pentaho Business Analytics through 9.1 does not properly verify uploaded user files, which allows an authenticated user to upload various files of different file types. Specifically, a .jsp file is not allowed, but a ...
CVE-2020-24666
- EPSS 0.21%
- Veröffentlicht 29.01.2021 19:15:13
- Zuletzt bearbeitet 21.11.2024 05:15:36
The Analysis Report in Hitachi Vantara Pentaho through 7.x - 8.x contains a stored Cross-site scripting vulnerability, which allows an authenticated remote users to execute arbitrary JavaScript code. Specifically, the vulnerability lies in the 'Displ...
CVE-2020-24669
- EPSS 0.21%
- Veröffentlicht 29.01.2021 19:15:13
- Zuletzt bearbeitet 21.11.2024 05:15:36
The New Analysis Report in Hitachi Vantara Pentaho through 7.x - 8.x contains a DOM-based Cross-site scripting vulnerability, which allows an authenticated remote users to execute arbitrary JavaScript code. Specifically, the vulnerability lies in the...
CVE-2020-24670
- EPSS 0.21%
- Veröffentlicht 29.01.2021 19:15:13
- Zuletzt bearbeitet 21.11.2024 05:15:36
The Dashboard Editor in Hitachi Vantara Pentaho through 7.x - 8.x contains a reflected Cross-site scripting vulnerability, which allows an authenticated remote users to execute arbitrary JavaScript code. Specifically, the vulnerability lies in the 't...
CVE-2020-24664
- EPSS 0.21%
- Veröffentlicht 29.01.2021 19:15:12
- Zuletzt bearbeitet 21.11.2024 05:15:35
The dashboard Editor in Hitachi Vantara Pentaho through 7.x - 8.x contains a reflected Cross-site scripting vulnerability, which allows an authenticated remote users to execute arbitrary JavaScript code. Specifically, the vulnerability lies in the 'p...
CVE-2020-24665
- EPSS 0.67%
- Veröffentlicht 29.01.2021 19:15:12
- Zuletzt bearbeitet 21.11.2024 05:15:35
The Dashboard Editor in Hitachi Vantara Pentaho through 7.x - 8.x contains an XML Entity Expansion injection vulnerability, which allows an authenticated remote users to trigger a denial of service (DoS) condition. Specifically, the vulnerability lie...