CVE-2025-0758 - CVE House
Back to Database
Status published Medium CVE-2025-0758

Hitachi Vantara Pentaho Business Analytics Server - Incorrect Permission Assignment for Critical Resource

Vulnerability Description

Overview  The product specifies permissions for a security-critical resource in a way that allows that resource to be read or modified by unintended actors. (CWE-732)  Description  Hitachi Vantara Pentaho Business Analytics Server prior to versions 10.2.0.2, including 9.3.x and 8.3.x, is installed with Karaf JMX beans enabled and accessible by default.  Impact  When the vulnerability is leveraged, a user with local execution privileges can access functionality exposed by Karaf beans contained in the product.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2025-0758

Credits & Attribution

The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:

  • Hitachi Group Member

Affected Vendor

Hitachi Vantara

View all reports →

Affected Software

Pentaho Business Analytics Server
Vulnerable Versions:
1.0, 10.0

Timeline

Official Publish: April 16th, 2025
Last Modified: April 17th, 2025
Added to House: July 22nd, 2026

CVSS Vectors

V3: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:H

Weaknesses (CWE)