HIGH

CVE-2021-31602

CVSS v3

7.5

HIGH

EPSS Score

92.8%

exploit probability

CISA KEV

No

known exploited

Exploitation

SSVC status

Description

An issue was discovered in Hitachi Vantara Pentaho through 9.1 and Pentaho Business Intelligence Server through 7.x. The Security Model has different layers of Access Control. One of these layers is the applicationContext security, which is defined in the applicationContext-spring-security.xml file. The default configuration allows an unauthenticated user with no previous knowledge of the platform settings to extract pieces of information without possessing valid credentials.

Technical details

Published
11/8/2021

Frequently asked questions

What is CVE-2021-31602?

An issue was discovered in Hitachi Vantara Pentaho through 9.1 and Pentaho Business Intelligence Server through 7.x. The Security Model has different layers of Access Control. One of these layers is the applicationContext security, which is defined in the applicationContext-spring-security.xml file. The default configuration allows an unauthenticated user with no previous knowledge of the platform settings to extract pieces of information without possessing valid credentials.

Is CVE-2021-31602 actively exploited?

Active exploitation of CVE-2021-31602 has not been confirmed. The EPSS score is 92.8%, indicating the estimated probability of exploitation in the next 30 days.

What is the CVSS score for CVE-2021-31602?

CVE-2021-31602 has a CVSS v3 base score of 7.5 (HIGH severity).

Is CVE-2021-31602 affecting your environment?

Use isMalicious to check if any of your IPs or domains are associated with this vulnerability's IOCs.