Information Disclosure: User Enumeration in Hitachi Vantara Pentaho

Information Disclosure: User Enumeration in Hitachi Vantara Pentaho

CVE-2021-31600 · MEDIUM Severity

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N

An issue was discovered in Hitachi Vantara Pentaho through 9.1 and Pentaho Business Intelligence Server through 7.x. They implement a series of web services using the SOAP protocol to allow scripting interaction with the backend server. An authenticated user (regardless of privileges) can list all valid usernames.

Learn more about our Web App Pen Testing.