6.8

CVSS4.0

CVE-2025-0112 - Cortex XDR Agent: Local Windows User Can Disable the Agent

A problem with a detection mechanism in the Palo Alto Networks Cortex XDR agent on Windows devices enables a user with Windows non-administrative privileges to disable the agent. This vulnerability can also be leveraged by malware to disable the Cortex XDR agent and then perform malicious activity.

📅 Published: Feb. 19, 2025, 11:44 p.m. 🔄 Last Modified: Feb. 20, 2025, 5:23 p.m.

6.5

CVSS3.1

CVE-2024-37363 - Hitachi Vantara Pentaho Business Analytics Server - Incorrect Authorization

The product does not perform an authorization check when an actor attempts to access a resource or perform an action. (CWE-862)  Hitachi Vantara Pentaho Business Analytics Server versions before 10.2.0.0 and 9.3.0.8, including 8.3.x, do not correctly perform an authorization check in the data…

📅 Published: Feb. 19, 2025, 11:40 p.m. 🔄 Last Modified: Feb. 20, 2025, 5:23 p.m.

6.3

CVSS3.1

CVE-2024-37362 - Hitachi Vantara Pentaho Data Integration & Analytics - Insufficiently Protected Credentials

The product transmits or stores authentication credentials, but it uses an insecure method that is susceptible to unauthorized interception and/or retrieval. (CWE-522)   Hitachi Vantara Pentaho Data Integration & Analytics versions before 10.2.0.0 and 9.3.0.8, including 8.3.x, discloses data…

📅 Published: Feb. 19, 2025, 11:34 p.m. 🔄 Last Modified: Feb. 20, 2025, 5:23 p.m.

6.5

CVSS3.1

CVE-2024-6697 - Hitachi Vantara Pentaho Business Analytics Server - Improper Handling of Insufficient Permissions o…

The product does not handle or incorrectly handles when it has insufficient privileges to access resources or functionality as specified by their permissions. This may cause it to follow unexpected code paths that may leave the product in an invalid state. (CWE-280)   Hitachi Vantara Pentaho …

📅 Published: Feb. 19, 2025, 11:32 p.m. 🔄 Last Modified: July 12, 2025, 10:16 p.m.

8.8

CVSS4.0

CVE-2024-12284 - Authenticated privilege escalation

Authenticated privilege escalation in NetScaler Console and NetScaler Agent allows.

📅 Published: Feb. 19, 2025, 11:30 p.m. 🔄 Last Modified: Feb. 26, 2026, 7:08 p.m.

4.9

CVSS3.1

CVE-2024-6696 - Hitachi Vantara Pentaho Business Analytics Server - Insufficient Granularity of Access Control

The product implements access controls via a policy or other feature with the intention to disable or restrict accesses (reads and/or writes) to assets in a system from untrusted agents. However, implemented access controls lack required granularity, which renders the control policy too broad becau…

📅 Published: Feb. 19, 2025, 11:29 p.m. 🔄 Last Modified: July 12, 2025, 10:23 p.m.

9.9

CVSS3.1

CVE-2024-37361 - Hitachi Vantara Pentaho Business Analytics Server - Deserialization of Untrusted Data

The application deserializes untrusted data without sufficiently verifying that the resulting data will be valid. (CWE-502)   Hitachi Vantara Pentaho Business Analytics Server versions before 10.2.0.0 and 9.3.0.9, including 8.3.x, deserialize untrusted JSON data without constraining the parse…

📅 Published: Feb. 19, 2025, 11:25 p.m. 🔄 Last Modified: July 12, 2025, 3:42 p.m.

4.4

CVSS3.1

CVE-2024-37360 - Hitachi Vantara Pentaho Business Analytics Server - Improper Neutralization of Input During Web Pag…

Hitachi Vantara Pentaho Business Analytics Server - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')   The software does not neutralize or incorrectly neutralize user-controllable input before it is placed in output that is used as a web page that is serve…

📅 Published: Feb. 19, 2025, 11:01 p.m. 🔄 Last Modified: July 12, 2025, 10:31 p.m.

8.6

CVSS3.1

CVE-2024-37359 - Hitachi Vantara Pentaho Business Analytics Server – Server Side Request Forgery

The web server receives a URL or similar request from an upstream component and retrieves the contents of this URL, but it does not sufficiently ensure that the request is being sent to the expected destination. (CWE-918)   Hitachi Vantara Pentaho Business Analytics Server versions before 10…

📅 Published: Feb. 19, 2025, 10:58 p.m. 🔄 Last Modified: July 12, 2025, 4:01 p.m.

8.8

CVSS3.1

CVE-2024-5705 - Hitachi Vantara Pentaho Business Analytics Server - Incorrect Authorization

The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check. This allows attackers to bypass intended access restrictions. (CWE-863)     Hitachi Vantara Pentaho Business Analytics Server versions…

📅 Published: Feb. 19, 2025, 10:55 p.m. 🔄 Last Modified: July 12, 2025, 10:16 p.m.
Total resulsts: 343975
Page 6161 of 34,398
« previous page » next page
Filters