target entity

Hitachi Vantara

2 source-linked records in the current knowledge graph.

high

CVE-2022-43769: Hitachi Vantara Pentaho BA Server Special Element Injection Vulnerability

Hitachi Vantara Pentaho BA Server contains a special element injection vulnerability that allows an attacker to inject Spring templates into properties files, allowing for arbitrary command execution. Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CVE-2022-43769EPSS 97.7%Hitachi VantaraPentaho Business Analytics (BA) Server
CISA KEV ↗ · unattributed attribution
high

CVE-2022-43939: Hitachi Vantara Pentaho BA Server Authorization Bypass Vulnerability

Hitachi Vantara Pentaho BA Server contains a use of non-canonical URL paths for authorization decisions vulnerability that enables an attacker to bypass authorization. Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CVE-2022-43939EPSS 92.3%Hitachi VantaraPentaho Business Analytics (BA) Server
CISA KEV ↗ · unattributed attribution