An issue was discovered in Hitachi Vantara Pentaho through 9.1 and Pentaho Business Intelligence Server through 7.x. They implement a series of web services using the SOAP protocol to allow scripting interaction with the backend server. An authenticated user (regardless of privileges) can list all valid usernames.
2021-11-08T04:15:08.160
2024-11-21T06:05:58.370
Modified
CVSSv3.1: 4.3 (MEDIUM)
AV:N/AC:L/Au:S/C:P/I:N/A:N
8.0
2.9
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | hitachi | vantara_pentaho | ≤ 9.1.0.0 | Yes |
Application | hitachi | vantara_pentaho_business_intelligence_server | ≤ 7.1 | Yes |