CVE-2022-43769: Hitachi Vantara Pentaho BA Server Special Element Injection Vulnerability
Hitachi Vantara Pentaho BA Server contains a special element injection vulnerability that allows an attacker to inject Spring templates into properties files, allowing for arbitrary command execution.
Other sources
Hitachi Vantara Pentaho Business Analytics Server prior to versions 9.4.0.1 and 9.3.0.2, including 8.3.x allow certain web services to set property values which contain Spring templates that are interpreted downstream.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Hitachi Vantara Pentaho Business Analytics Serverto a version that resolves this vulnerability.Fixed in 9.4.0.1 - Upgrade
Upgrade
Hitachi Vantara Pentaho Business Analytics Serverto a version that resolves this vulnerability.Fixed in 9.3.0.2 - Compensating control
Follow applicable BOD 22-01 guidance for cloud services.
- Compensating control
Discontinue use of the product if mitigations are unavailable.
Event History
Frequently Asked Questions
What is the severity of CVE-2022-43769?
The severity of CVE-2022-43769 is high with a severity value of 7.2.
Which versions of Hitachi Vantara Pentaho Business Analytics Server are affected by CVE-2022-43769?
Hitachi Vantara Pentaho Business Analytics Server versions prior to 9.4.0.1 and 9.3.0.2, including 8.3.x, are affected by CVE-2022-43769.
How can an attacker exploit CVE-2022-43769?
An attacker can exploit CVE-2022-43769 by setting property values containing Spring templates that are interpreted downstream in certain web services.
How do I fix CVE-2022-43769?
To fix CVE-2022-43769, it is recommended to update Hitachi Vantara Pentaho Business Analytics Server to version 9.4.0.1 or 9.3.0.2, or a later version that addresses the vulnerability.
What are the references for CVE-2022-43769?
The references for CVE-2022-43769 are: 1. [Packet Storm Security](http://packetstormsecurity.com/files/172296/Pentaho-Business-Server-Authentication-Bypass-SSTI-Code-Execution.html) 2. [Pentaho Support](https://support.pentaho.com/hc/en-us/articles/14455561548301--Resolved-Pentaho-BA-Server-Failure-to-Sanitize-Special-Elements-into-a-Different-Plane-Special-Element-Injection-Versions-before-9-4-0-1-and-9-3-0-2-including-8-3-x-Impacted-CVE-2022-43769-)