HIGH

CVE-2022-43769

Hitachi Vantara Pentaho Business Analytics Server 2023-04-03 CVSS v3.1
CVSS
7.2
KEV

Description

Hitachi Vantara Pentaho Business Analytics Server prior to versions 9.4.0.1 and 9.3.0.2, including 8.3.x allow certain web services to set property values which contain Spring templates that are interpreted downstream.

Summary dbcve.org

This is a Server-Side Template Injection (SSTI) vulnerability in Hitachi Vantara Pentaho Business Analytics Server. Certain web services allow users to set property values containing Spring template syntax (e.g., #{...}, ${...}), which are then interpreted/processed by the Spring framework downstream, potentially leading to remote code execution.

Mitigation

Upgrade to Pentaho Business Analytics Server versions 9.4.0.1 or 9.3.0.2 or later. If immediate upgrading is not feasible, restrict network access to the vulnerable web services and consider deploying a WAF with rules to detect and block Spring template syntax in request parameters.

Proof of Concept

Weakness (CWE)

CWE-74 Injection
CWE-94 Code Injection

EPSS Score

97.67%
Probability of exploitation in next 30 days
99.9th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE