CVE-2025-24910
CVSS 3.1 Score 4.9 of 10 (medium)
Details
Summary
CVE-2025-24910 is a vulnerability affecting Hitachi Vantara Pentaho Business Analytics Server versions prior to 10.2.0.2. The issue lies in the way the server handles XML External Entity References. An attacker can exploit this vulnerability (CWE-611) by defining an entity in an XML file with a URI pointing to a local or remote file. If the processing application echoes back the data, the attacker can gain access to the contents of the file. In the case of a file URI, the attacker can read local files, potentially gaining sensitive information. With an http URI, the attacker can force the application to make outgoing requests, allowing them to bypass firewall restrictions or hide their source during attacks.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Vendors
- Hitachi Vantara