Hitachi Vantara Pentaho Business Analytics Server prior to versions 9.4.0.1 and 9.3.0.2, including 8.3.x allow certain web services to set property values which contain Spring templates that are interpreted downstream.
History

Thu, 13 Feb 2025 16:45:00 +0000

Type Values Removed Values Added
Description Hitachi Vantara Pentaho Business Analytics Server prior to versions 9.4.0.1 and 9.3.0.2, including 8.3.x allow certain web services to set property values which contain Spring templates that are interpreted downstream.  Hitachi Vantara Pentaho Business Analytics Server prior to versions 9.4.0.1 and 9.3.0.2, including 8.3.x allow certain web services to set property values which contain Spring templates that are interpreted downstream.
Title Hitachi Vantara Pentaho Business Analytics Server - Failure to Sanitize Special Elements into a Different Plane (Special Element Injection) Hitachi Vantara Pentaho Business Analytics Server - Failure to Sanitize Special Elements into a Different Plane (Special Element Injection)

Tue, 11 Feb 2025 15:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


cve-icon MITRE

Status: PUBLISHED

Assigner: HITVAN

Published:

Updated: 2025-02-13T16:33:38.763Z

Reserved: 2022-10-26T12:55:14.326Z

Link: CVE-2022-43769

cve-icon Vulnrichment

Updated: 2024-08-03T13:40:06.548Z

cve-icon NVD

Status : Modified

Published: 2023-04-03T18:15:07.703

Modified: 2025-02-13T17:15:46.603

Link: CVE-2022-43769

cve-icon Redhat

No data.