CVE-2025-0757

CVSS 3.1 Score 4.4 of 10 (medium)

Details

Published Apr 16, 2025
Updated: Apr 17, 2025
CWE ID 79

Summary

CVE-2025-0757 is a vulnerability affecting Hitachi Vantara Pentaho Business Analytics Server versions prior to 10.2.0.2, including 9.3.x and 8.3.x. The issue arises from the software's failure to neutralize or incorrectly neutralize user-controllable input, as per CWE-79. This allows a malicious URL to inject content into the Analyzer plugin interface. Malicious scripts injected in this manner enable the attacker to perform various malicious activities, including data theft and unauthorized web requests on behalf of the victim, potentially leading to severe consequences for both the victim and affected websites, especially if the victim holds administrator privileges.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share