Pentaho Business Analytics / Pentaho Business Server 9.1 User Enumeration

Discussion in 'News Aggregator' started by Packet Storm, 6 Nov 2021.

  1. Packet Storm

    Packet Storm Guest

    Pentaho implements a series of web services using the SOAP protocol to allow scripting interaction with the backend server. HAWSEC identified that the services userRoleListService and ServiceAction exposed through the /pentaho/webservices/userRoleListService and /pentaho/ServiceAction?action=SecurityDetails endpoints are not enforcing sufficient access controls. Specifically, an authenticated user can list all application usernames present in the Jackrabbit Repository.

    Continue reading...
     

Share This Page

Loading...