← Back to CVE List
Vulnerability Intelligence Report
Hitachi Vantara Pentaho Business Analytics Server - Deserialization of Untrusted Data

CVE-2024-37361

The application deserializes untrusted data without sufficiently verifying that the resulting data will be valid. (CWE-502)   Hitachi Vantara Pentaho Business Analytics Server versions before 10.2.0.0 and 9.3.0.9, including 8.3.x, deserialize untrusted JSON data without constraining the parser to approved classes and methods.   When developers place no restrictions on "gadget chains," or series of instances and method invocations that can self-execute during the deserialization process (i.e., before the object is returned to the caller), it is sometimes possible for attackers to leverage them to perform unauthorized actions.

No Active Exploit Signals
CVSS Base Score
9.9
CRITICAL
Exploitability:3.2
Impact Score:6.1
EPSS Probability:0.47%
Executive Threat Verdict
Evaluating...
Evaluating Threat Landscape...
Assessing known weaponization, exploitation telemetry, and federal advisories.
Attack Surface
—
Authentication
—
Weaponization
—
SSVC Action
—

Weaknesses (CWE)

CWE-502 ↗CWE-502 Deserialization of Untrusted Data

Affected Products & Versions

Vendor Product Affected Versions
Hitachi Vantara Pentaho Data Integration & Analytics 10.0 < 10.2.0.0 (affected)
Hitachi Vantara Pentaho Business Analytics Server 1.0 < 9.3.0.9 (affected)

References & Technical Advisories

No reference links found.

Threat Intelligence Signals

EPSS Score
0.470%

Identity & Timeline

StatusPUBLISHED
Assigning AuthorityHITVAN
Reserved2024-06-06T15:36:41
Published2025-02-19T23:25:33
Last Updated2025-02-20T17:21:31

LINK COPIED TO CLIPBOARD