Vulnerability Intelligence Report
Hitachi Vantara Pentaho Business Analytics Server - Deserialization of Untrusted Data
CVE-2024-37361
The application deserializes untrusted data without sufficiently verifying that the resulting data will be valid. (CWE-502) Hitachi Vantara Pentaho Business Analytics Server versions before 10.2.0.0 and 9.3.0.9, including 8.3.x, deserialize untrusted JSON data without constraining the parser to approved classes and methods. When developers place no restrictions on "gadget chains," or series of instances and method invocations that can self-execute during the deserialization process (i.e., before the object is returned to the caller), it is sometimes possible for attackers to leverage them to perform unauthorized actions.
No Active Exploit Signals
CVSS Base Score
9.9
CRITICAL
Exploitability:3.2
Impact Score:6.1
EPSS Probability:0.47%
Executive Threat Verdict
Evaluating...
Evaluating Threat Landscape...
Assessing known weaponization, exploitation telemetry, and federal advisories.
Attack Surface
—
Authentication
—
Weaponization
—
SSVC Action
—
Weaknesses (CWE)
CWE-502 ↗CWE-502 Deserialization of Untrusted Data
Affected Products & Versions
| Vendor | Product | Affected Versions |
|---|---|---|
| Hitachi Vantara | Pentaho Data Integration & Analytics | 10.0 < 10.2.0.0 (affected) |
| Hitachi Vantara | Pentaho Business Analytics Server | 1.0 < 9.3.0.9 (affected) |
References & Technical Advisories
No reference links found.
Threat Intelligence Signals
EPSS Score
0.470%
GitHub Advisory
Identity & Timeline
| Status | PUBLISHED |
| Assigning Authority | HITVAN |
| Reserved | 2024-06-06T15:36:41 |
| Published | 2025-02-19T23:25:33 |
| Last Updated | 2025-02-20T17:21:31 |
Community Chatter & Buzz