TROYANOSYVIRUS
Voltar para CVEs

CVE-2022-43939

HIGHCISA KEV
8.6

Descricao

Hitachi Vantara Pentaho Business Analytics Server versions before 9.4.0.1 and 9.3.0.2, including 8.3.x contain security restrictions using non-canonical URLs which can be circumvented.

Detalhes CVE

Pontuacao CVSS v3.18.6
SeveridadeHIGH
Vetor CVSSCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H
Vetor de ataqueNETWORK
ComplexidadeLOW
Privilegios necessariosNONE
Interacao do usuarioNONE
Publicado4/3/2023
Ultima modificacao10/24/2025
Fontekev
Avistamentos honeypot0

CISA KEV

FornecedorHitachi Vantara
ProdutoPentaho Business Analytics (BA) Server
Nome da vulnerabilidadeHitachi Vantara Pentaho BA Server Authorization Bypass Vulnerability
Data inclusao KEV2025-03-03
Prazo de remediacao2025-03-24
Uso em ransomwareUnknown

Produtos afetados

hitachi:vantara_pentaho_business_analytics_server

Fraquezas (CWE)

CWE-647

Correlacoes IOC

Sem correlacoes registradas

This product uses data from the NVD API but is not endorsed or certified by the NVD.