CVE-2025-11158: Hitachi Vantara Pentaho Data Integration & Analytics - Missing Authorization
Hitachi Vantara Pentaho Data Integration & Analytics versions before 10.2.0.6, including 9.3.x and 8.3.x, do not restrict Groovy scripts in new PRPT reports published by users, allowing insertion of arbitrary scripts and leading to a RCE.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-11158?
CVE-2025-11158 is a medium-severity vulnerability due to missing authorization in Hitachi Vantara Pentaho Data Integration & Analytics.
How do I fix CVE-2025-11158?
To remediate CVE-2025-11158, upgrade Hitachi Vantara Pentaho Data Integration & Analytics to version 10.2.0.6 or later.
What versions are affected by CVE-2025-11158?
CVE-2025-11158 affects versions before 10.2.0.6, as well as 9.3.x and 8.3.x versions of Hitachi Vantara Pentaho Data Integration & Analytics.
What impact does CVE-2025-11158 have?
CVE-2025-11158 allows unauthorized users to execute arbitrary Groovy scripts in new PRPT reports, compromising system integrity.
Is CVE-2025-11158 a widespread issue?
The extent of CVE-2025-11158's impact depends on the deployment of the affected versions in organizations using Hitachi Vantara Pentaho.