CVE-2024-6697

CVSS 3.1 Score 6.5 of 10 (medium)

Details

Published Feb 20, 2025
CWE ID 280

Summary

CVE-2024-6697 is a vulnerability affecting Hitachi Vantara Pentaho Business Analytics Server versions prior to 10.2.0.0 and 9.3.0.9, including 8.3.x. This issue involves incorrect permission handling, allowing an adversary to exploit a legitimate capability of the application, leading to a denial of service. The server may follow unintended code paths when insufficient privileges are present, resulting in an invalid state. (CWE-280)

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share