PT-2026-43484 · Hitachi Vantara · Pentaho Data Integration & Analytics
CVSS v3.1
6.3
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L |
Name of the Vulnerable Software and Affected Versions
Hitachi Vantara Pentaho Data Integration & Analytics versions prior to 10.2.0.6
Hitachi Vantara Pentaho Data Integration & Analytics versions prior to 11.0.0.0
Description
Incorrect permission assignment occurs because Access Control Lists (ACLs), which are sets of rules that define permissions for users or systems to access specific resources, are not applied to certain API endpoints related to platform mail notifications.
Recommendations
Update to version 10.2.0.6 or later.
Update to version 11.0.0.0 or later.
Fix
Incorrect Permission
Insufficiently Protected Credentials
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Pentaho Data Integration & Analytics