First published: Mon Apr 03 2023(Updated: )
Hitachi Vantara Pentaho Business Analytics Server prior to versions 9.4.0.1 and 9.3.0.2, including 8.3.x is installed with a sample HSQLDB data source configured with stored procedures enabled.
Credit: security.vulnerabilities@hitachivantara.com
Affected Software | Affected Version | How to fix |
---|---|---|
Hitachi Vantara Pentaho Business Analytics Server | >=8.3.0.0<9.3.0.2 | |
Hitachi Vantara Pentaho Business Analytics Server | =9.4.0.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2022-43773 is high with a severity value of 8.8.
Hitachi Vantara Pentaho Business Analytics Server prior to versions 9.4.0.1 and 9.3.0.2, including 8.3.x, are affected by CVE-2022-43773.
Hitachi Vantara Pentaho Business Analytics Server is installed with a sample HSQLDB data source configured with stored procedures enabled, which allows the vulnerability to be exploited.
To fix CVE-2022-43773, upgrade to Hitachi Vantara Pentaho Business Analytics Server version 9.4.0.1 or 9.3.0.2, or apply any available patches or security updates provided by the vendor.
You can find more information about CVE-2022-43773 on the official Hitachi Vantara Pentaho support website at the following link: [https://support.pentaho.com/hc/en-us/articles/14453135249165--Resolved-Pentaho-BA-Server-Incorrect-Permission-Assignment-for-Critical-Resource-Versions-before-9-4-0-1-and-9-3-0-2-including-8-3-x-Impacted-CVE-2022-43773-](https://support.pentaho.com/hc/en-us/articles/14453135249165--Resolved-Pentaho-BA-Server-Incorrect-Permission-Assignment-for-Critical-Resource-Versions-before-9-4-0-1-and-9-3-0-2-including-8-3-x-Impacted-CVE-2022-43773-)