CVE-2015-6940
The GetResource servlet in Pentaho Business Analytics (BA) Suite 4.5.x, 4.8.x, and 5.0.x through 5.2.x and Pentaho Data Integration (PDI) Suite 4.3.x, 4.4.x, and 5.0.x through 5.2.x does not restrict access to files in the pentaho-solutions/system…
Does this matter?
Lower severity and a low EPSS score (2.30%). Track it; it rarely justifies an emergency change on its own.
Description
The GetResource servlet in Pentaho Business Analytics (BA) Suite 4.5.x, 4.8.x, and 5.0.x through 5.2.x and Pentaho Data Integration (PDI) Suite 4.3.x, 4.4.x, and 5.0.x through 5.2.x does not restrict access to files in the pentaho-solutions/system folder, which allows remote attackers to obtain passwords and other sensitive information via a file name in the resource parameter.
- CVSS 2.0
- 5.0 MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:N
- EPSS
- 2.30% probability · 82th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-200
- Affected
- pentaho/data integration · pentaho/business analytics
- Source
- cve@mitre.org
References
- http://packetstormsecurity.com/files/133601/Pentaho-5.2.x-BA-Suite-PDI-Information-Disclosure.htmlExploit
- http://www.securityfocus.com/archive/1/536477/100/0/threaded
- https://support.pentaho.com/entries/78884125-Security-Vulnerability-Announcement-Feb-2015Patch, Vendor Advisory
- http://packetstormsecurity.com/files/133601/Pentaho-5.2.x-BA-Suite-PDI-Information-Disclosure.htmlExploit
- http://www.securityfocus.com/archive/1/536477/100/0/threaded
- https://support.pentaho.com/entries/78884125-Security-Vulnerability-Announcement-Feb-2015Patch, Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.