CVE-2024-28984: Hitachi Pentaho Business Analytics Server

Medium severity, CVSS 6.1. EPSS: 0.3% chance of exploitation in the next 30 days.

Hitachi Vantara Pentaho Business Analytics Server prior to versions 10.1.0.0 and 9.3.0.7, including 8.3.x allow a malicious URL to inject content into the Analyzer plugin interface.

Affected products

  • Hitachi Pentaho Business Analytics Server: before 9.3.0.7 (fixed in 9.3.0.7); after 9.3.1.0, before 10.1.0.0 (fixed in 10.1.0.0)

Published 2024-06-26. Last modified 2026-06-17.