CVE-2025-11159: Hitachi Vantara Pentaho Data Integration & Analytics - Dependency on Vulnerable Third-Party Component
Hitachi Vantara Pentaho Data Integration & Analytics of all versions contain a JDBC driver for H2 databases which is vulnerable to external script execution when a new connection is created by a data source administrator.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-11159?
CVE-2025-11159 is considered a high-severity vulnerability due to its potential for external script execution.
How do I fix CVE-2025-11159?
To mitigate CVE-2025-11159, upgrade to versions 10.2.0.7 or 11.0.0.0 or later of Hitachi Vantara Pentaho Data Integration & Analytics.
What software is affected by CVE-2025-11159?
CVE-2025-11159 affects all versions of Hitachi Vantara Pentaho Data Integration & Analytics that use a vulnerable H2 JDBC driver.
What type of vulnerability is CVE-2025-11159?
CVE-2025-11159 is a vulnerability involving external script execution due to a problematic database driver in the affected software.
Can CVE-2025-11159 impact system security?
Yes, CVE-2025-11159 can significantly compromise system security by allowing unauthorized script execution during connection creation.