UploadService in Hitachi Vantara Pentaho Business Analytics through 9.1 does not properly verify uploaded user files, which allows an authenticated user to upload various files of different file types. Specifically, a .jsp file is not allowed, but a .jsp. file is allowed (and leads to remote code execution).
2021-11-08T04:15:08.377
2024-11-21T06:10:56.857
Modified
CVSSv3.1: 2.7 (LOW)
AV:N/AC:L/Au:S/C:P/I:P/A:P
8.0
6.4
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | hitachi | vantara_pentaho | ≤ 9.1.0.0 | Yes |