Executive brief
Hitachi Vantara Pentaho Business Analytics Server contains a special element injection vulnerability where certain web services allow setting property values containing Spring templates. These templates are interpreted downstream, potentially leading to arbitrary command execution.
Affected products
- Hitachi Vantara Pentaho Business Analytics Server prior to 9.4.0.1 and 9.3.0.2, including 8.3.x
Timeline
- 2023-04-12: disclosed: Initial NIST analysis and disclosure.
- 2025-03-03: kev added: Added to CISA Known Exploited Vulnerabilities (KEV) catalog.
- 2025-03-03: exploited: Reported as exploited in the wild.