First published: Mon Apr 03 2023(Updated: )
Hitachi Vantara Pentaho Business Analytics Server prior to versions 9.4.0.0 and 9.3.0.2, including 8.3.x display the full parametrized SQL query in an error message when an invalid character is used within a Pentaho Report (*.prpt).
Credit: security.vulnerabilities@hitachivantara.com
Affected Software | Affected Version | How to fix |
---|---|---|
Hitachi Vantara Pentaho Business Analytics Server | <9.3.0.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2022-4770 is medium with a severity value of 4.3.
CVE-2022-4770 affects Hitachi Vantara Pentaho Business Analytics Server versions prior to 9.4.0.0 and 9.3.0.2, including 8.3.x.
CVE-2022-4770 is a vulnerability that allows the display of full parametrized SQL query in an error message when an invalid character is used within a Pentaho Report (*.prpt).
To fix CVE-2022-4770, upgrade Hitachi Vantara Pentaho Business Analytics Server to version 9.4.0.0 or 9.3.0.2.
More information about CVE-2022-4770 can be found at the following reference: [link](https://support.pentaho.com/hc/en-us/articles/14455209015949--Resolved-Hitachi-Vantara-Pentaho-Business-Analytics-Server-Generation-of-Error-Message-Containing-Sensitive-Information-Versions-before-9-4-0-0-and-9-3-0-2-including-8-3-x-Impacted-CVE-2022-4770-).