CVE-2022-43938: Hitachi Vantara Pentaho Business Analytics Server - Improper Neutralization of Directives in Statically Saved Code ('Static Code Injection')
Hitachi Vantara Pentaho Business Analytics Server prior to versions 9.4.0.1 and 9.3.0.2, including 8.3.x cannot allow a system administrator to disable scripting capabilities of Pentaho Reports (.prpt) through the JVM script manager.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID of this issue?
The vulnerability ID of this issue is CVE-2022-43938.
What is the severity of CVE-2022-43938?
The severity of CVE-2022-43938 is high.
What is the affected software?
The affected software is Hitachi Vantara Pentaho Business Analytics Server prior to versions 9.4.0.1 and 9.3.0.2, including 8.3.x.
What is the description of CVE-2022-43938?
CVE-2022-43938 is a vulnerability in Hitachi Vantara Pentaho Business Analytics Server that allows a system administrator to disable scripting capabilities of Pentaho Reports (*.prpt) through the JVM script manager.
How can I fix CVE-2022-43938?
To fix CVE-2022-43938, update Hitachi Vantara Pentaho Business Analytics Server to versions 9.4.0.1 or 9.3.0.2.