Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2024-37362

Опубликовано: 20 фев. 2025
Источник: nvd
CVSS3: 6.3
EPSS Низкий

Описание

The product transmits or stores authentication credentials, but it uses an insecure method that is susceptible to unauthorized interception and/or retrieval. (CWE-522)

 

Hitachi Vantara Pentaho Data Integration & Analytics versions before 10.2.0.0 and 9.3.0.8, including 8.3.x, discloses database passwords when saving connections to RedShift.

 

Products must not disclose sensitive information without cause. Disclosure of sensitive information can lead to further exploitation.

EPSS

Процентиль: 27%
0.00095
Низкий

6.3 Medium

CVSS3

Дефекты

CWE-522

Связанные уязвимости

CVSS3: 6.3
github
12 месяцев назад

The product transmits or stores authentication credentials, but it uses an insecure method that is susceptible to unauthorized interception and/or retrieval. (CWE-522)   Hitachi Vantara Pentaho Data Integration & Analytics versions before 10.2.0.0 and 9.3.0.8, including 8.3.x, discloses database passwords when saving connections to RedShift.   Products must not disclose sensitive information without cause. Disclosure of sensitive information can lead to further exploitation.

CVSS3: 6.3
fstec
12 месяцев назад

Уязвимость программного средства для интеграции данных и аналитики Hitachi Vantara Pentaho Data Integration & Analytics, связанная с недостаточной защитой регистрационных данных, позволяющая нарушителю раскрыть конфиденциальную информацию

EPSS

Процентиль: 27%
0.00095
Низкий

6.3 Medium

CVSS3

Дефекты

CWE-522