CVE-2022-4771: Hitachi Vantara Pentaho Business Analytics Server - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
Published Apr 3, 2023
·Updated
Hitachi Vantara Pentaho Business Analytics Server prior to versions 9.4.0.1 and 9.3.0.2, including 8.3.x allow a malicious URL to inject content into the Pentaho User Console through session variables.
Affected Software
2 affected components
Hitachi Vantara Pentaho Business Analytics Server<9.3.0.2
Hitachi Vantara Pentaho Business Analytics Server=9.4.0.0
Event History
Apr 3, 2023
CVE Published
via MITRE·06:58 PM
Data Sourced
via MITRE·06:58 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the vulnerability ID for Hitachi Vantara Pentaho Business Analytics Server?
The vulnerability ID for Hitachi Vantara Pentaho Business Analytics Server is CVE-2022-4771.
2
What is the severity rating of CVE-2022-4771?
CVE-2022-4771 has a severity rating of medium.
3
Which versions of Hitachi Vantara Pentaho Business Analytics Server are affected by CVE-2022-4771?
Hitachi Vantara Pentaho Business Analytics Server versions 9.4.0.1, 9.3.0.2, and 8.3.x are affected by CVE-2022-4771.
4
How does CVE-2022-4771 impact Hitachi Vantara Pentaho Business Analytics Server?
CVE-2022-4771 allows a malicious URL to inject content into the Pentaho User Console through session variables.
5
Is there a fix available for CVE-2022-4771?
Yes, a fix is available for CVE-2022-4771. Upgrade to version 9.4.0.1 or 9.3.0.2 of Hitachi Vantara Pentaho Business Analytics Server.