CVE-2021-34685
08.11.2021, 04:15
UploadService in Hitachi Vantara Pentaho Business Analytics through 9.1 does not properly verify uploaded user files, which allows an authenticated user to upload various files of different file types. Specifically, a .jsp file is not allowed, but a .jsp. file is allowed (and leads to remote code execution).Enginsight
Vendor | Product | Version |
---|---|---|
hitachi | vantara_pentaho | 𝑥 ≤ 9.1.0.0 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration
References