CVE-2022-43939: Hitachi Vantara Pentaho BA Server Authorization Bypass Vulnerability
Hitachi Vantara Pentaho BA Server contains a use of non-canonical URL paths for authorization decisions vulnerability that enables an attacker to bypass authorization.
Other sources
Hitachi Vantara Pentaho Business Analytics Server versions before 9.4.0.1 and 9.3.0.2, including 8.3.x contain security restrictions using non-canonical URLs which can be circumvented.
— NVD
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Hitachi Vantara Pentaho Business Analytics Server / Pentaho BI Serverto a version that resolves this vulnerability.Fixed in 9.4.0.1 - Upgrade
Upgrade
Hitachi Vantara Pentaho Business Analytics Server / Pentaho BI Serverto a version that resolves this vulnerability.Fixed in 9.3.0.2 - Remove
Remove
Hitachi Vantara Pentaho Business Analytics Server / Pentaho BI Serverfrom your environment.If vendor mitigations are unavailable or cannot be applied, discontinue use of the product and uninstall/remove it from affected environments.
- Compensating control
Apply vendor-provided mitigations for the non-canonical URL authorization bypass per vendor instructions. For deployments in cloud environments, follow applicable BOD 22-01 guidance to mitigate exposure.
Event History
Frequently Asked Questions
What is CVE-2022-43939?
CVE-2022-43939 is a vulnerability in Hitachi Vantara Pentaho Business Analytics Server that allows security restrictions using non-canonical URLs to be bypassed.
What versions of Hitachi Vantara Pentaho Business Analytics Server are affected by CVE-2022-43939?
Versions before 9.4.0.1 and 9.3.0.2, including 8.3.x, are affected by CVE-2022-43939.
What is the severity of CVE-2022-43939?
CVE-2022-43939 has a severity rating of 9.8 (critical).
How can the security restrictions using non-canonical URLs be circumvented in Hitachi Vantara Pentaho Business Analytics Server?
The security restrictions using non-canonical URLs in Hitachi Vantara Pentaho Business Analytics Server can be circumvented by exploiting the vulnerability.
Where can I find more information about CVE-2022-43939?
You can find more information about CVE-2022-43939 at the following references: [http://packetstormsecurity.com/files/172296/Pentaho-Business-Server-Authentication-Bypass-SSTI-Code-Execution.html](http://packetstormsecurity.com/files/172296/Pentaho-Business-Server-Authentication-Bypass-SSTI-Code-Execution.html) and [https://support.pentaho.com/hc/en-us/articles/14455394120333--Resolved-Pentaho-BA-Server-Use-of-Non-Canonical-URL-Paths-for-Authorization-Decisions-Versions-before-9-4-0-1-and-9-3-0-2-including-8-3-x-Impacted-CVE-2022-43939-](https://support.pentaho.com/hc/en-us/articles/14455394120333--Resolved-Pentaho-BA-Server-Use-of-Non-Canonical-URL-Paths-for-Authorization-Decisions-Versions-before-9-4-0-1-and-9-3-0-2-including-8-3-x-Impacted-CVE-2022-43939-)