Description

Overview  The product specifies permissions for a security-critical resource in a way that allows that resource to be read or modified by unintended actors. (CWE-732)  Description  Hitachi Vantara Pentaho Business Analytics Server prior to versions 10.2.0.2, including 9.3.x and 8.3.x, is installed with Karaf JMX beans enabled and accessible by default.  Impact  When the vulnerability is leveraged, a user with local execution privileges can access functionality exposed by Karaf beans contained in the product.

INFO

Published Date :

2025-04-16T22:12:29.724Z

Last Modified :

2025-04-17T13:10:38.993Z

Source :

HITVAN
AFFECTED PRODUCTS

The following products are affected by CVE-2025-0758 vulnerability.

Vendors Products
Hitachi
  • Vantara Pentaho Business Analytics Server

CVSS Vulnerability Scoring System

Detailed values of each vector for above chart.
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality Impact
Integrity Impact
Availability Impact