CVE-2022-43769
Hitachi Vantara · Published April 3, 2023
7.2
CVSS v3.1
HIGHCISA KEV — Federal agencies must patch by deadline
Actively exploited in the wild
Patch availableGet patch
Description
Hitachi Vantara Pentaho Business Analytics Server prior to versions 9.4.0.1 and 9.3.0.2, including 8.3.x allow certain web services to set property values which contain Spring templates that are interpreted downstream.
Affected Products
- Vantara Pentaho Business Analytics Server < 9.3.0.2
- Vantara Pentaho Business Analytics Server
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H