The product transmits or stores authentication credentials, but it uses an insecure method that is susceptible to unauthorized interception and/or retrieval. (CWE-522)
Hitachi Vantara Pentaho Data Integration & Analytics versions before 10.2.0.0 and 9.3.0.8, including 8.3.x, discloses database passwords when saving connections to RedShift.
Products must not disclose sensitive information without cause. Disclosure of sensitive information can lead to further exploitation.
Metrics
Affected Vendors & Products
History
Thu, 20 Feb 2025 18:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Wed, 19 Feb 2025 23:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | The product transmits or stores authentication credentials, but it uses an insecure method that is susceptible to unauthorized interception and/or retrieval. (CWE-522) Hitachi Vantara Pentaho Data Integration & Analytics versions before 10.2.0.0 and 9.3.0.8, including 8.3.x, discloses database passwords when saving connections to RedShift. Products must not disclose sensitive information without cause. Disclosure of sensitive information can lead to further exploitation. | |
Title | Hitachi Vantara Pentaho Data Integration & Analytics - Insufficiently Protected Credentials | |
Weaknesses | CWE-522 | |
References |
| |
Metrics |
cvssV3_1
|

Status: PUBLISHED
Assigner: HITVAN
Published: 2025-02-19T23:34:29.558Z
Updated: 2025-02-20T17:23:41.440Z
Reserved: 2024-06-06T15:36:41.050Z
Link: CVE-2024-37362

Updated: 2025-02-20T17:23:38.577Z

Status : Received
Published: 2025-02-20T00:15:19.630
Modified: 2025-02-20T00:15:19.630
Link: CVE-2024-37362

No data.