First published: Mon Apr 03 2023(Updated: )
Hitachi Vantara Pentaho Business Analytics Server prior to versions 9.4.0.1 and 9.3.0.2, including 8.3.x allow certain web services to set property values which contain Spring templates that are interpreted downstream.
Credit: security.vulnerabilities@hitachivantara.com
Affected Software | Affected Version | How to fix |
---|---|---|
Hitachi Vantara Pentaho Business Analytics Server | >=8.3.0.0<9.3.0.2 | |
Hitachi Vantara Pentaho Business Analytics Server | =9.4.0.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2022-43769 is high with a severity value of 7.2.
Hitachi Vantara Pentaho Business Analytics Server versions prior to 9.4.0.1 and 9.3.0.2, including 8.3.x, are affected by CVE-2022-43769.
An attacker can exploit CVE-2022-43769 by setting property values containing Spring templates that are interpreted downstream in certain web services.
To fix CVE-2022-43769, it is recommended to update Hitachi Vantara Pentaho Business Analytics Server to version 9.4.0.1 or 9.3.0.2, or a later version that addresses the vulnerability.
The references for CVE-2022-43769 are: 1. [Packet Storm Security](http://packetstormsecurity.com/files/172296/Pentaho-Business-Server-Authentication-Bypass-SSTI-Code-Execution.html) 2. [Pentaho Support](https://support.pentaho.com/hc/en-us/articles/14455561548301--Resolved-Pentaho-BA-Server-Failure-to-Sanitize-Special-Elements-into-a-Different-Plane-Special-Element-Injection-Versions-before-9-4-0-1-and-9-3-0-2-including-8-3-x-Impacted-CVE-2022-43769-)