CVE-2022-43940: Hitachi Vantara Pentaho Business Analytics Server - Incorrect Authorization
Hitachi Vantara Pentaho Business Analytics Server versions before 9.4.0.1 and 9.3.0.2, including 8.3.x do not correctly perform an authorization check in the data source management service.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2022-43940?
The severity of CVE-2022-43940 is high with a CVSS score of 8.8.
Which versions of Pentaho Business Analytics Server are affected by CVE-2022-43940?
Pentaho Business Analytics Server versions before 9.4.0.1 and 9.3.0.2, including 8.3.x, are affected by CVE-2022-43940.
What is the issue with Hitachi Vantara Pentaho Business Analytics Server in relation to CVE-2022-43940?
Hitachi Vantara Pentaho Business Analytics Server versions before 9.4.0.1 and 9.3.0.2, including 8.3.x, do not correctly perform an authorization check in the data source management service.
How can I fix the vulnerability in CVE-2022-43940?
To fix the vulnerability in CVE-2022-43940, update to version 9.4.0.1 or 9.3.0.2 of Hitachi Vantara Pentaho Business Analytics Server.
Where can I find more information about CVE-2022-43940?
More information about CVE-2022-43940 can be found at the following link: [https://support.pentaho.com/hc/en-us/articles/14456609400973--Resolved-Pentaho-BA-Server-Incorrect-Authorization-Versions-before-9-4-0-1-and-9-3-0-2-including-8-3-x-Impacted-CVE-2022-43940-](https://support.pentaho.com/hc/en-us/articles/14456609400973--Resolved-Pentaho-BA-Server-Incorrect-Authorization-Versions-before-9-4-0-1-and-9-3-0-2-including-8-3-x-Impacted-CVE-2022-43940-).