Hitachi Vantara Pentaho Business Analytics Server prior to versions 9.4.0.1 and 9.3.0.2, including 8.3.x allow certain web services to set property values which contain Spring templates that are interpreted downstream.
References
Configurations
Configuration 1 (hide)
|
History
13 Mar 2025, 19:52
Type | Values Removed | Values Added |
---|---|---|
References | () http://packetstormsecurity.com/files/172296/Pentaho-Business-Server-Authentication-Bypass-SSTI-Code-Execution.html - Exploit |
13 Feb 2025, 17:15
Type | Values Removed | Values Added |
---|---|---|
References | () http://packetstormsecurity.com/files/172296/Pentaho-Business-Server-Authentication-Bypass-SSTI-Code-Execution.html - | |
References | () https://support.pentaho.com/hc/en-us/articles/14455561548301--Resolved-Pentaho-BA-Server-Failure-to-Sanitize-Special-Elements-into-a-Different-Plane-Special-Element-Injection-Versions-before-9-4-0-1-and-9-3-0-2-including-8-3-x-Impacted-CVE-2022-43769- - Vendor Advisory | |
Summary | Hitachi Vantara Pentaho Business Analytics Server prior to versions 9.4.0.1 and 9.3.0.2, including 8.3.x allow certain web services to set property values which contain Spring templates that are interpreted downstream. |
11 May 2023, 18:15
Type | Values Removed | Values Added |
---|---|---|
References |
|
|
Summary | Hitachi Vantara Pentaho Business Analytics Server prior to versions 9.4.0.1 and 9.3.0.2, including 8.3.x allow certain web services to set property values which contain Spring templates that are interpreted downstream. |
12 Apr 2023, 18:51
Type | Values Removed | Values Added |
---|---|---|
CPE | cpe:2.3:a:hitachi:vantara_pentaho_business_analytics_server:9.4.0.0:*:*:*:*:*:*:* cpe:2.3:a:hitachi:vantara_pentaho_business_analytics_server:*:*:*:*:*:*:*:* |
|
First Time |
Hitachi
Hitachi vantara Pentaho Business Analytics Server |
|
CWE | CWE-94 | |
References | (MISC) https://support.pentaho.com/hc/en-us/articles/14455561548301--Resolved-Pentaho-BA-Server-Failure-to-Sanitize-Special-Elements-into-a-Different-Plane-Special-Element-Injection-Versions-before-9-4-0-1-and-9-3-0-2-including-8-3-x-Impacted-CVE-2022-43769- - Vendor Advisory | |
CVSS |
v2 : v3 : |
v2 : unknown
v3 : 7.2 |
03 Apr 2023, 18:34
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2023-04-03 18:15
Updated : 2025-03-13 19:52
NVD link : CVE-2022-43769
Mitre link : CVE-2022-43769
JSON object : View
Products Affected
hitachi
- vantara_pentaho_business_analytics_server
CWE
CWE-94
Improper Control of Generation of Code ('Code Injection')