CVE-2022-3960: Hitachi Vantara Pentaho Business Analytics Server - Improper Neutralization of Directives in Statically Saved Code ('Static Code Injection')
Hitachi Vantara Pentaho Business Analytics Server prior to versions 9.4.0.1 and 9.3.0.2, including 8.3.x cannot allow a system administrator to disable scripting capabilities of the Community Dashboard Editor (CDE) plugin.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2022-3960?
CVE-2022-3960 is a vulnerability in Hitachi Vantara Pentaho Business Analytics Server that allows a system administrator to disable the scripting capabilities of the Community Dashboard Editor (CDE) plugin.
What versions of Hitachi Vantara Pentaho Business Analytics Server are affected by CVE-2022-3960?
Versions prior to 9.4.0.1 and 9.3.0.2, including 8.3.x, of Hitachi Vantara Pentaho Business Analytics Server are affected by CVE-2022-3960.
How severe is CVE-2022-3960?
CVE-2022-3960 has a severity value of 6.3, which is considered medium.
What is the CWE identifier for CVE-2022-3960?
The CWE identifier for CVE-2022-3960 is CWE-94 and CWE-96.
How can I fix CVE-2022-3960?
To fix CVE-2022-3960, it is recommended to update Hitachi Vantara Pentaho Business Analytics Server to version 9.4.0.1 or 9.3.0.2, which include the necessary security patches.