CVE Vulnerabilities

CVE-2021-45446

Exposure of Information Through Directory Listing

Published: Nov 02, 2022 | Modified: Nov 21, 2024
CVSS 3.x
7.5
HIGH
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

A vulnerability in

Hitachi Vantara Pentaho Business Analytics Server versions before 9.2.0.2 and 8.3.0.25 does not cascade the hidden property to the children of the Home folder.  This directory listing provides an attacker with the complete index of all the resources located inside the directory.

Weakness

The product inappropriately exposes a directory listing with an index of all the resources located inside of the directory.

Affected Software

NameVendorStart VersionEnd Version
Vantara_pentahoHitachi8.3.0.0 (including)8.3.0.25 (excluding)
Vantara_pentahoHitachi9.2.0.0 (including)9.2.0.2 (excluding)

Potential Mitigations

References