First published: Mon Apr 03 2023(Updated: )
Hitachi Vantara Pentaho Business Analytics Server prior to versions 9.4.0.1 and 9.3.0.2, including 8.3.x allow a malicious URL to inject content into the Pentaho User Console through session variables.
Credit: security.vulnerabilities@hitachivantara.com
Affected Software | Affected Version | How to fix |
---|---|---|
Hitachi Vantara Pentaho Business Analytics Server | <9.3.0.2 | |
Hitachi Vantara Pentaho Business Analytics Server | =9.4.0.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for Hitachi Vantara Pentaho Business Analytics Server is CVE-2022-4771.
CVE-2022-4771 has a severity rating of medium.
Hitachi Vantara Pentaho Business Analytics Server versions 9.4.0.1, 9.3.0.2, and 8.3.x are affected by CVE-2022-4771.
CVE-2022-4771 allows a malicious URL to inject content into the Pentaho User Console through session variables.
Yes, a fix is available for CVE-2022-4771. Upgrade to version 9.4.0.1 or 9.3.0.2 of Hitachi Vantara Pentaho Business Analytics Server.