CVE-2022-43772: Hitachi Vantara Pentaho Business Analytics Server - Insertion of Sensitive Information into Log File
Hitachi Vantara Pentaho Business Analytics Server versions before 9.4.0.0 and 9.3.0.1, including 8.3.x with the Big Data Plugin expose the username and password of clusters in clear text into system logs.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2022-43772?
CVE-2022-43772 is a vulnerability found in Hitachi Vantara Pentaho Business Analytics Server versions before 9.4.0.0 and 9.3.0.1, including 8.3.x with the Big Data Plugin.
How severe is CVE-2022-43772?
CVE-2022-43772 has a severity rating of medium with a CVSS score of 6.5.
What does CVE-2022-43772 expose?
CVE-2022-43772 exposes the username and password of clusters in clear text into system logs.
Which version of Hitachi Vantara Pentaho Business Analytics Server is affected by CVE-2022-43772?
CVE-2022-43772 affects versions before 9.4.0.0 and 9.3.0.1, including 8.3.x with the Big Data Plugin.
How can I fix CVE-2022-43772?
To fix CVE-2022-43772, update your Hitachi Vantara Pentaho Business Analytics Server to version 9.4.0.0 or 9.3.0.1.