Vulnerabilities > Hitachi > Vantara Pentaho > 8.3.0.9

DATE CVE VULNERABILITY TITLE RISK
2021-11-08 CVE-2021-34685 Unrestricted Upload of File with Dangerous Type vulnerability in Hitachi Vantara Pentaho
UploadService in Hitachi Vantara Pentaho Business Analytics through 9.1 does not properly verify uploaded user files, which allows an authenticated user to upload various files of different file types.
network
low complexity
hitachi CWE-434
6.5
2021-01-29 CVE-2020-24666 Cross-site Scripting vulnerability in Hitachi Vantara Pentaho
The Analysis Report in Hitachi Vantara Pentaho through 7.x - 8.x contains a stored Cross-site scripting vulnerability, which allows an authenticated remote users to execute arbitrary JavaScript code.
network
hitachi CWE-79
3.5