CVE-2025-24911

CVSS 3.1 Score 4.9 of 10 (medium)

Details

Published Apr 16, 2025
Updated: Apr 17, 2025
CWE ID 611

Summary

CVE-2025-24911 is a vulnerability affecting Hitachi Vantara Pentaho Business Analytics Server versions prior to 10.2.0.2, including 9.3.x and 8.3.x. The issue lies in the application's XML parser, which fails to adequately protect against out-of-band XML External Entity References (CWE-611). An attacker can manipulate this vulnerability by submitting an XML file containing a maliciously defined external entity with a file:// URI. When the application reads the content of the URI, it unintentionally exposes the local file's contents. Additionally, attackers can exploit the vulnerability using URIs with other schemes, such as http://, to evade firewall restrictions or mask the origin of attacks, including port scanning.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share