CVE-2024-28984: Hitachi Pentaho Business Analytics Server
Medium severity, CVSS 6.1. EPSS: 0.3% chance of exploitation in the next 30 days.
Hitachi Vantara Pentaho Business Analytics Server prior to versions 10.1.0.0 and 9.3.0.7, including 8.3.x allow a malicious URL to inject content into the Analyzer plugin interface.
Affected products
- Hitachi Pentaho Business Analytics Server: before 9.3.0.7 (fixed in 9.3.0.7); after 9.3.1.0, before 10.1.0.0 (fixed in 10.1.0.0)
Published 2024-06-26. Last modified 2026-06-17.