---
cve: "CVE-2021-45446"
severity: "MEDIUM"
cvss: 5.0
epss: "42%"
vendor: "Hitachi Vantara"
kev: false
exploited: false
published: "2022-11-02 15:15:09"
tags: [cve, security, medium]
source: tsecurity.de CVE-Dossier
exported: "2026-09-18T03:49:29+02:00"
---

# CVE-2021-45446

> 5.0 MEDIUM

## Beschreibung

A vulnerability in 

Hitachi Vantara Pentaho Business Analytics Server versions before 9.2.0.2 and 
8.3.0.25 does not cascade the hidden property to the children of the Home folder.  This directory listing provides an attacker with the complete index of all the resources located 
inside the directory.

## CVSS-Vektor

```
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:N/A:N
```

| Metrik | Wert | Bewertung |
|---|---|---|
| AV Angriffsvektor | Netzwerk | bad |
| AC Komplexität | Gering | bad |
| PR Privilegien | Gering | warn |
| UI Interaktion | Keine | bad |
| S Scope | Verändert | bad |
| C Vertraulichkeit | Gering | warn |
| I Integrität | Keine | good |
| A Verfügbarkeit | Keine | good |

## Referenzen

- <https://support.pentaho.com/hc/en-us/articles/6744813983501>

---
_Exportiert aus dem [tsecurity.de CVE-Dossier](https://tsecurity.de/cve?cve=CVE-2021-45446) · Datenquellen: EUVD (ENISA), NVD, OSV, CISA KEV, FIRST EPSS, Exploit-DB, BSI BITS_
