Overview
The software generates an error message that includes sensitive information about its environment, users, or associated data. (CWE-209)
Products Affected
Hitachi Vantara Pentaho Data Integration and Analytics Community Dashboard Framework prior to versions 10.2.0.4, including 9.3.0.x and 8.3.x
Description
Hitachi Vantara Pentaho Data Integration and Analytics Community Dashboard Framework prior to versions 10.2.0.4, including 9.3.0.x and 8.3.x display the full server stack trace when encountering an error within the GetCdfResource servlet.
Impact
An attacker may use the contents of error messages to help launch another, more focused attack. An attack using SQL injection (CWE-89) might not initially succeed, but an error message could reveal the malformed query, which would expose query logic and possibly even passwords or other sensitive information used within the query.
Action
The defect may be mitigated now by removing the Community Dashboard Framework plugin from the software installation.
We recommend you upgrade to the latest Hitachi Vantara Pentaho Business Analytics Server release or Service Pack where this vulnerability is addressed.
Please review the Pentaho End-of-Life policy to ensure you are up to date.
Comments