CVE-2025-0758

CVSS 3.1 Score 6.1 of 10 (medium)

Details

Published Apr 16, 2025
Updated: Apr 17, 2025
CWE ID 732

Summary

CVE-2025-0758 is a vulnerability affecting Hitachi Vantara Pentaho Business Analytics Server versions prior to 10.2.0.2, including 9.3.x and 8.3.x. The issue stems from the product's misconfiguration, allowing security-critical resources to be read or modified by unintended actors due to improper permissions (CWE-732). Specifically, the server comes with Karaf JMX beans enabled and publicly accessible, enabling users with local execution privileges to access functionality exposed by these beans. Successful exploitation of this vulnerability could lead to significant security implications.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share