Pentaho 5.2.x BA Suite / PDI Information Disclosure

Discussion in 'News Aggregator' started by Packet Storm, 19 Sep 2015.

  1. Packet Storm

    Packet Storm Guest

    Pentaho version 5.2.x GA BA Suite and PDI allow unauthenticated access to configuration files. The GetResource servlet, a vestige of the old platform UI, allows unauthenticated access to resources in the pentaho-solutions/system folder. Specifically vulnerable are properties files that may reveal passwords.

    Continue reading...
     

Share This Page

Loading...