CVE-2022-43769
גבוהה 7.2 מנוצלת בשטח (KEV)
ניצול פעיל מאומת — קטלוג CISA KEV
- שם
- Hitachi Vantara Pentaho BA Server Special Element Injection Vulnerability
- נוסף לקטלוג
- יעד טיפול (פדרלי)
- פעולה נדרשת
- Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
תיאור (מקור, אנגלית)
Hitachi Vantara Pentaho Business Analytics Server prior to versions 9.4.0.1 and 9.3.0.2, including 8.3.x allow certain web services to set property values which contain Spring templates that are interpreted downstream.
מדדים
- CVSS 3.1
-
7.2 (HIGH)
מקור הציון: NVD
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H - EPSS — סבירות ניצול
- 98% (אחוזון 100) נכון ל-25/7/2026
- CWE
- CWE-74, CWE-94
מוצרים מושפעים
hitachi: vantara pentaho business analytics server
קישורים
- https://support.pentaho.com/hc/en-us/articles/14455561548301--Resolved-Pentaho… Vendor Advisory
- https://support.pentaho.com/hc/en-us/articles/14455561548301--Resolved-Pentaho… Vendor Advisory
- http://packetstormsecurity.com/files/172296/Pentaho-Business-Server-Authentica… Exploit
- http://packetstormsecurity.com/files/172296/Pentaho-Business-Server-Authentica… Exploit
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-202… US Government Resource