#VU50240 XML Entity Expansion in Vantara Pentaho Business Analytics Server - CVE-2020-24665
Published: January 29, 2021 / Updated: February 2, 2021
Vantara Pentaho Business Analytics Server
Hitachi
Description
The vulnerability allows a remote attacker to perform a denial o service (DoS) attack.
The vulnerability exists due to improper restrictions on XML entities in the Dashboard Editor. A remote authenticated attacker can send a specially crafted request and cause a denial of service condition on the target system.