CVE-2022-4770: Hitachi Vantara Pentaho Business Analytics Server - Generation of Error Message Containing Sensitive Information
Hitachi Vantara Pentaho Business Analytics Server prior to versions 9.4.0.0 and 9.3.0.2, including 8.3.x display the full parametrized SQL query in an error message when an invalid character is used within a Pentaho Report (.prpt).
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2022-4770?
The severity of CVE-2022-4770 is medium with a severity value of 4.3.
How does CVE-2022-4770 affect Hitachi Vantara Pentaho Business Analytics Server?
CVE-2022-4770 affects Hitachi Vantara Pentaho Business Analytics Server versions prior to 9.4.0.0 and 9.3.0.2, including 8.3.x.
What is the vulnerability of CVE-2022-4770?
CVE-2022-4770 is a vulnerability that allows the display of full parametrized SQL query in an error message when an invalid character is used within a Pentaho Report (*.prpt).
How can I fix CVE-2022-4770?
To fix CVE-2022-4770, upgrade Hitachi Vantara Pentaho Business Analytics Server to version 9.4.0.0 or 9.3.0.2.
Where can I find more information about CVE-2022-4770?
More information about CVE-2022-4770 can be found at the following reference: [link](https://support.pentaho.com/hc/en-us/articles/14455209015949--Resolved-Hitachi-Vantara-Pentaho-Business-Analytics-Server-Generation-of-Error-Message-Containing-Sensitive-Information-Versions-before-9-4-0-0-and-9-3-0-2-including-8-3-x-Impacted-CVE-2022-4770-).