Show filters
1,712 Total Results
Displaying 271-280 of 1,712
Sort by:
Attacker Value
Unknown

CVE-2022-3695

Disclosure Date: April 11, 2023 (last updated February 24, 2025)
Hitachi Vantara Pentaho Business Analytics Server prior to versions 9.3.0.0, 9.2.0.4 and 8.3.0.27 allow a malicious URL to inject content into a dashboard when the CDE plugin is present.   
Attacker Value
Unknown

CVE-2023-29185

Disclosure Date: April 11, 2023 (last updated February 24, 2025)
SAP NetWeaver AS for ABAP (Business Server Pages) - versions 700, 701, 702, 731, 740, 750, 751, 752, 753, 754, 755, 756, 757, allows an attacker authenticated as a non-administrative user to craft a request with certain parameters in certain circumstances which can consume the server's resources sufficiently to make it unavailable over the network without any user interaction.
Attacker Value
Unknown

CVE-2023-28765

Disclosure Date: April 11, 2023 (last updated February 24, 2025)
An attacker with basic privileges in SAP BusinessObjects Business Intelligence Platform (Promotion Management) - versions 420, 430, can get access to lcmbiar file and further decrypt the file. After this attacker can gain access to BI user’s passwords and depending on the privileges of the BI user, the attacker can perform operations that can completely compromise the application.
Attacker Value
Unknown

CVE-2022-4771

Disclosure Date: April 03, 2023 (last updated February 24, 2025)
Hitachi Vantara Pentaho Business Analytics Server prior to versions 9.4.0.1 and 9.3.0.2, including 8.3.x allow a malicious URL to inject content into the Pentaho User Console through session variables. 
Attacker Value
Unknown

CVE-2022-4770

Disclosure Date: April 03, 2023 (last updated February 24, 2025)
Hitachi Vantara Pentaho Business Analytics Server prior to versions 9.4.0.0 and 9.3.0.2, including 8.3.x display the full parametrized SQL query in an error message when an invalid character is used within a Pentaho Report (*.prpt). 
Attacker Value
Unknown

CVE-2022-4769

Disclosure Date: April 03, 2023 (last updated February 24, 2025)
Hitachi Vantara Pentaho Business Analytics Server prior to versions 9.4.0.0 and 9.3.0.2, including 8.3.x display the target path on host when a file is uploaded with an invalid character in its name. 
Attacker Value
Unknown

CVE-2022-43941

Disclosure Date: April 03, 2023 (last updated February 24, 2025)
Hitachi Vantara Pentaho Business Analytics Server versions before 9.4.0.1 and 9.3.0.2, including 8.3.x do not correctly protect the Post Analysis service endpoint of the data access plugin against out-of-band XML External Entity Reference. 
Attacker Value
Unknown

CVE-2022-43940

Disclosure Date: April 03, 2023 (last updated February 24, 2025)
Hitachi Vantara Pentaho Business Analytics Server versions before 9.4.0.1 and 9.3.0.2, including 8.3.x do not correctly perform an authorization check in the data source management service. 
Attacker Value
Unknown

CVE-2022-43938

Disclosure Date: April 03, 2023 (last updated February 24, 2025)
Hitachi Vantara Pentaho Business Analytics Server prior to versions 9.4.0.1 and 9.3.0.2, including 8.3.x cannot allow a system administrator to disable scripting capabilities of Pentaho Reports (*.prpt) through the JVM script manager. 
Attacker Value
Unknown

CVE-2022-43772

Disclosure Date: April 03, 2023 (last updated February 24, 2025)
Hitachi Vantara Pentaho Business Analytics Server versions before 9.4.0.0 and 9.3.0.1, including 8.3.x with the Big Data Plugin expose the username and password of clusters in clear text into system logs.