CVE-2025-9122: Hitachi Vantara Pentaho Business Analytics Server - Generation of Error Message Containing Sensitive Information
Hitachi Vantara Pentaho Data Integration and Analytics Community Dashboard Framework prior to versions 10.2.0.4, including 9.3.0.x and 8.3.x display the full server stack trace when encountering an error within the GetCdfResource servlet.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-9122?
CVE-2025-9122 has a severity rating that could lead to disclosure of sensitive information due to the exposure of full server stack traces.
How do I fix CVE-2025-9122?
To fix CVE-2025-9122, upgrade to Hitachi Vantara Pentaho Data Integration and Analytics Community Dashboard Framework version 10.2.0.4 or later.
Which versions of Hitachi Vantara Pentaho are affected by CVE-2025-9122?
CVE-2025-9122 affects versions prior to 10.2.0.4, including versions 9.3.0.x and 8.3.x.
What vulnerability does CVE-2025-9122 address?
CVE-2025-9122 addresses the issue of sensitive information exposure through full server stack traces in error messages.
Is it safe to use versions before 10.2.0.4 of Hitachi Vantara Pentaho?
Using versions before 10.2.0.4 of Hitachi Vantara Pentaho is not safe due to the risk of sensitive information disclosure.