TROYANOSYVIRUS
Back to CVEs

CVE-2022-43769

HIGHCISA KEV
8.8

Description

Hitachi Vantara Pentaho Business Analytics Server prior to versions 9.4.0.1 and 9.3.0.2, including 8.3.x allow certain web services to set property values which contain Spring templates that are interpreted downstream.

CVE Details

CVSS v3.1 Score8.8
SeverityHIGH
CVSS VectorCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Attack VectorNETWORK
ComplexityLOW
Privileges RequiredLOW
User InteractionNONE
Published4/3/2023
Last Modified10/24/2025
Sourcekev
Honeypot Sightings0

CISA KEV

VendorHitachi Vantara
ProductPentaho Business Analytics (BA) Server
Vulnerability NameHitachi Vantara Pentaho BA Server Special Element Injection Vulnerability
KEV Date Added2025-03-03
Remediation Due Date2025-03-24
Ransomware UseUnknown

Affected Products

hitachi:vantara_pentaho_business_analytics_server

Weaknesses (CWE)

CWE-74CWE-94

IOC Correlations

No correlations recorded

This product uses data from the NVD API but is not endorsed or certified by the NVD.