CVE-2025-9121: Hitachi Vantara Pentaho Business Analytics Server - Deserialization of Untrusted Data
Pentaho Data Integration and Analytics Community Dashboard Editor plugin versions before 10.2.0.4, including 9.3.0.x and 8.3.x, deserialize untrusted JSON data without constraining the parser to approved classes and methods.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-9121?
CVE-2025-9121 is considered a moderate severity vulnerability due to the potential for remote code execution through deserialization of untrusted JSON data.
How do I fix CVE-2025-9121?
To mitigate CVE-2025-9121, upgrade Pentaho Data Integration and Analytics Community Dashboard Editor plugin to version 10.2.0.4 or later.
Which versions are affected by CVE-2025-9121?
CVE-2025-9121 affects Pentaho Data Integration and Analytics Community Dashboard Editor plugin versions prior to 10.2.0.4, including 9.3.0.x and 8.3.x.
Can CVE-2025-9121 lead to data breaches?
Yes, exploitation of CVE-2025-9121 can potentially lead to unauthorized access and data breaches due to code execution vulnerabilities.
What components of Hitachi Vantara are affected by CVE-2025-9121?
CVE-2025-9121 impacts Hitachi Vantara Pentaho Business Analytics Server and Hitachi Vantara Pentaho Data Integration versions before 10.2.0.4.