CVSS v3
7.5
HIGH
EPSS Score
92.8 %
exploit probability
CISA KEV
No
known exploited
Exploitation
—
SSVC status
Description
An issue was discovered in Hitachi Vantara Pentaho through 9.1 and Pentaho Business Intelligence Server through 7.x. The Security Model has different layers of Access Control. One of these layers is the applicationContext security, which is defined in the applicationContext-spring-security.xml file. The default configuration allows an unauthenticated user with no previous knowledge of the platform settings to extract pieces of information without possessing valid credentials.
Technical details
- Published
- 2021-11-08
Frequently asked questions
What is CVE-2021-31602?
An issue was discovered in Hitachi Vantara Pentaho through 9.1 and Pentaho Business Intelligence Server through 7.x. The Security Model has different layers of Access Control. One of these layers is the applicationContext security, which is defined in the applicationContext-spring-security.xml file. The default configuration allows an unauthenticated user with no previous knowledge of the platform settings to extract pieces of information without possessing valid credentials.
Is CVE-2021-31602 actively exploited?
Active exploitation of CVE-2021-31602 has not been confirmed. The EPSS score is 92.8%, indicating the estimated probability of exploitation in the next 30 days.
What is the CVSS score for CVE-2021-31602?
CVE-2021-31602 has a CVSS v3 base score of 7.5 (HIGH severity).
Is CVE-2021-31602 affecting your environment?
Use isMalicious to check if any of your IPs or domains are associated with this vulnerability's IOCs.
No credit card required · 500 free checks/month · Free API key
Other 2021 vulnerabilities worth triaging
Ranked by exploit probability (EPSS).