Hitachi Vantara Pentaho Business Analytics Server prior to versions 9.4.0.1 and 9.3.0.2, including 8.3.x allow certain web services to set property values which contain Spring templates that are interpreted downstream.
References
Configurations
Configuration 1 (hide)
|
History
13 Mar 2025, 19:52
Type | Values Removed | Values Added |
---|---|---|
References | () http://packetstormsecurity.com/files/172296/Pentaho-Business-Server-Authentication-Bypass-SSTI-Code-Execution.html - Exploit |
13 Feb 2025, 17:15
Type | Values Removed | Values Added |
---|---|---|
Summary | (en) Hitachi Vantara Pentaho Business Analytics Server prior to versions 9.4.0.1 and 9.3.0.2, including 8.3.x allow certain web services to set property values which contain Spring templates that are interpreted downstream. |
Information
Published : 2023-04-03 18:15
Updated : 2025-03-13 19:52
NVD link : CVE-2022-43769
Mitre link : CVE-2022-43769
CVE.ORG link : CVE-2022-43769
JSON object : View
Products Affected
hitachi
- vantara_pentaho_business_analytics_server