6.5
CVSSv2

CVE-2021-34685

Published: 08/11/2021 Updated: 09/11/2021
CVSS v2 Base Score: 6.5 | Impact Score: 6.4 | Exploitability Score: 8
CVSS v3 Base Score: 7.2 | Impact Score: 5.9 | Exploitability Score: 1.2
VMScore: 580
Vector: AV:N/AC:L/Au:S/C:P/I:P/A:P

Vulnerability Summary

UploadService in Hitachi Vantara Pentaho Business Analytics up to and including 9.1 does not properly verify uploaded user files, which allows an authenticated user to upload various files of different file types. Specifically, a .jsp file is not allowed, but a .jsp. file is allowed (and leads to remote code execution).

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

hitachi vantara pentaho

Exploits

Pentaho allows users to upload various files of different file types The upload service is implemented under the /pentaho/UploadService endpoint The file types allowed by the application are csv, dat, txt, tar, zip, tgz, gz, gzip When uploading a file with an extension other than the allowed file types, the application responds with the error me ...