First published: Mon Apr 03 2023(Updated: )
Hitachi Vantara Pentaho Business Analytics Server prior to versions 9.4.0.0 and 9.3.0.2, including 8.3.x display the target path on host when a file is uploaded with an invalid character in its name.
Credit: security.vulnerabilities@hitachivantara.com
Affected Software | Affected Version | How to fix |
---|---|---|
Hitachi Vantara Pentaho Business Intelligence Server | <9.3.0.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID is CVE-2022-4769.
The severity of CVE-2022-4769 is medium with a CVSSv3 score of 4.3.
Hitachi Vantara Pentaho Business Analytics Server versions prior to 9.4.0.0 and 9.3.0.2, including 8.3.x, are affected by CVE-2022-4769.
CVE-2022-4769 allows an attacker to display the target path on the host when a file with an invalid character in its name is uploaded.
Yes, the fix for CVE-2022-4769 is available in versions 9.4.0.0 and 9.3.0.2 of Hitachi Vantara Pentaho Business Analytics Server.