S4E just found a high-severity finding from top 10 tcp port service scan
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
high·Product Based Web Vulnerabilities·Updated Jan 8, 2024

CVE-2021-31602 Scanner

CVE-2021-31602 scanner - Information Disclosure vulnerability in Hitachi Vantara Pentaho and Pentaho Business Intelligence Server

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsurl
CostFree
3.3k
Times Used
continuous scan runs
3.7k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2021-31602
7.5
CVSSmedium
Exploitable remotely over the internet · no authentication required.

An issue was discovered in Hitachi Vantara Pentaho through 9.1 and Pentaho Business Intelligence Server through 7.x. The Security Model has different layers of Access Control. One of these layers is the applicationContext security, which is defined in the applicationContext-spring-security.xml file. The default configuration allows an unauthenticated user with no previous knowledge of the platform settings to extract pieces of information without possessing valid credentials.

Attack Vector
Network
Privileges Req.
None
User Interaction
None
Affected
n/aby n/a
n/a
Updated Aug 21, 2026View on NVD →
Detail

Hitachi Vantara Pentaho and Pentaho Business Intelligence Server are widely used in the field of business intelligence. These products allow organizations to collect, analyze, and interpret data from various sources to make informed decisions. They are popular among businesses of all sizes due to their simple user interface, flexibility, and scalability. 

CVE-2021-31602 is a vulnerability that was recently discovered in Hitachi Vantara Pentaho through 9.1 and Pentaho Business Intelligence Server through 7.x. It lies in the different layers of the product's Access Control security model, specifically in the applicationContext security layer. The default configuration of this layer allows unauthorized users to extract sensitive information without possessing valid credentials, which can lead to potential data breaches. 

If this vulnerability is exploited, it can pose numerous threats to a business. It may result in data leakage and unauthorized access to confidential information, which can cause significant financial losses and damage the organization's reputation. Moreover, this can also lead to legal troubles due to data privacy laws which impose hefty fines on companies that fail to protect their clients' information. 

Businesses that are looking for reliable security solutions can turn to s4e.io. Their pro features enable organizations to easily detect vulnerabilities in their digital assets and take necessary precautions. Given that CVE-2021-31602 can have serious impacts on businesses, it is essential to stay vigilant and take preventative measures to safeguard their valuable data.

 

REFERENCES

Solution Advice

To prevent this issue from occurring, there are a few precautions that businesses can take: 

  • Apply vendor-supplied patches and updates promptly
  • Restrict access to critical systems to only authorized personnel
  • Regularly assess and test your security infrastructure to identify leaks and security gaps
  • Utilize security tools such as firewalls, intrusion detection systems, and antivirus software
  • Follow industry-standard security protocols such as using two-factor authentication and encryption 

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.