Описание
UploadService in Hitachi Vantara Pentaho Business Analytics through 9.1 does not properly verify uploaded user files, which allows an authenticated user to upload various files of different file types. Specifically, a .jsp file is not allowed, but a .jsp. file is allowed (and leads to remote code execution).
Ссылки
- ExploitThird Party AdvisoryVDB Entry
- Vendor Advisory
- ExploitThird Party AdvisoryVDB Entry
- Vendor Advisory
Уязвимые конфигурации
Конфигурация 1Версия до 9.1.0.0 (включая)
cpe:2.3:a:hitachi:vantara_pentaho:*:*:*:*:*:*:*:*
EPSS
Процентиль: 83%
0.0197
Низкий
2.7 Low
CVSS3
7.2 High
CVSS3
6.5 Medium
CVSS2
Дефекты
CWE-434
Связанные уязвимости
github
больше 3 лет назад
UploadService in Hitachi Vantara Pentaho Business Analytics through 9.1 does not properly verify uploaded user files, which allows an authenticated user to upload various files of different file types. Specifically, a .jsp file is not allowed, but a .jsp. file is allowed (and leads to remote code execution).
EPSS
Процентиль: 83%
0.0197
Низкий
2.7 Low
CVSS3
7.2 High
CVSS3
6.5 Medium
CVSS2
Дефекты
CWE-434