CVE-2025-0757
CVSS 3.1 Score 4.4 of 10 (medium)
Details
Summary
CVE-2025-0757 is a vulnerability affecting Hitachi Vantara Pentaho Business Analytics Server versions prior to 10.2.0.2, including 9.3.x and 8.3.x. The issue arises from the software's failure to neutralize or incorrectly neutralize user-controllable input, as per CWE-79. This allows a malicious URL to inject content into the Analyzer plugin interface. Malicious scripts injected in this manner enable the attacker to perform various malicious activities, including data theft and unauthorized web requests on behalf of the victim, potentially leading to severe consequences for both the victim and affected websites, especially if the victim holds administrator privileges.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Vendors
- Hitachi Vantara