First published: Mon Apr 03 2023(Updated: )
Hitachi Vantara Pentaho Business Analytics Server versions before 9.4.0.1 and 9.3.0.2, including 8.3.x do not correctly perform an authorization check in the data source management service.
Credit: security.vulnerabilities@hitachivantara.com
Affected Software | Affected Version | How to fix |
---|---|---|
Hitachi Vantara Pentaho Business Analytics Server | <9.3.0.2 | |
Hitachi Vantara Pentaho Business Analytics Server | =9.4.0.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2022-43940 is high with a CVSS score of 8.8.
Pentaho Business Analytics Server versions before 9.4.0.1 and 9.3.0.2, including 8.3.x, are affected by CVE-2022-43940.
Hitachi Vantara Pentaho Business Analytics Server versions before 9.4.0.1 and 9.3.0.2, including 8.3.x, do not correctly perform an authorization check in the data source management service.
To fix the vulnerability in CVE-2022-43940, update to version 9.4.0.1 or 9.3.0.2 of Hitachi Vantara Pentaho Business Analytics Server.
More information about CVE-2022-43940 can be found at the following link: [https://support.pentaho.com/hc/en-us/articles/14456609400973--Resolved-Pentaho-BA-Server-Incorrect-Authorization-Versions-before-9-4-0-1-and-9-3-0-2-including-8-3-x-Impacted-CVE-2022-43940-](https://support.pentaho.com/hc/en-us/articles/14456609400973--Resolved-Pentaho-BA-Server-Incorrect-Authorization-Versions-before-9-4-0-1-and-9-3-0-2-including-8-3-x-Impacted-CVE-2022-43940-).