Required CVE Record Information
Description
Hitachi Vantara Pentaho Business Analytics Server versions before 9.4.0.1 and 9.3.0.3, including 8.3.x deserialize untrusted JSON data without constraining the parser to approved classes and methods.
CVSS 1 Total
Score | Severity | Version | Vector String |
---|---|---|---|
8.0 | HIGH | 3.1 | CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H |
Credits
- Clarence Liau finder
- Hitachi Group Member finder
Updated:
This container includes required additional information provided by the CVE Program for this vulnerability.