CVE-2022-43773: Hitachi Vantara Pentaho Business Analytics Server - Incorrect Permission Assignment for Critical Resource
Hitachi Vantara Pentaho Business Analytics Server prior to versions 9.4.0.1 and 9.3.0.2, including 8.3.x is installed with a sample HSQLDB data source configured with stored procedures enabled.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2022-43773?
The severity of CVE-2022-43773 is high with a severity value of 8.8.
Which versions of Hitachi Vantara Pentaho Business Analytics Server are affected by CVE-2022-43773?
Hitachi Vantara Pentaho Business Analytics Server prior to versions 9.4.0.1 and 9.3.0.2, including 8.3.x, are affected by CVE-2022-43773.
How is Hitachi Vantara Pentaho Business Analytics Server configured with stored procedures enabled vulnerable to CVE-2022-43773?
Hitachi Vantara Pentaho Business Analytics Server is installed with a sample HSQLDB data source configured with stored procedures enabled, which allows the vulnerability to be exploited.
How can I fix CVE-2022-43773?
To fix CVE-2022-43773, upgrade to Hitachi Vantara Pentaho Business Analytics Server version 9.4.0.1 or 9.3.0.2, or apply any available patches or security updates provided by the vendor.
Where can I find more information about CVE-2022-43773?
You can find more information about CVE-2022-43773 on the official Hitachi Vantara Pentaho support website at the following link: [https://support.pentaho.com/hc/en-us/articles/14453135249165--Resolved-Pentaho-BA-Server-Incorrect-Permission-Assignment-for-Critical-Resource-Versions-before-9-4-0-1-and-9-3-0-2-including-8-3-x-Impacted-CVE-2022-43773-](https://support.pentaho.com/hc/en-us/articles/14453135249165--Resolved-Pentaho-BA-Server-Incorrect-Permission-Assignment-for-Critical-Resource-Versions-before-9-4-0-1-and-9-3-0-2-including-8-3-x-Impacted-CVE-2022-43773-)