In Hitachi Vantara Pentaho BA Platform through 8.0, a CSRF issue exists in the Business Analytics application.
The web application does not, or cannot, sufficiently verify whether a request was intentionally provided by the user who sent the request, which could have originated from an unauthorized actor.
Link | Tags |
---|---|
http://jira.pentaho.com/browse/BISERVER-3562 | issue tracking third party advisory |
http://jira.pentaho.com/browse/BISERVER-6599 | issue tracking third party advisory |
http://www.securityfocus.com/bid/102200 | vdb entry |
http://jira.pentaho.com/browse/BISERVER-13207 | issue tracking third party advisory |