Executive brief
Hitachi Vantara Pentaho Business Analytics Server uses non-canonical URL paths for authorization decisions, allowing remote attackers to bypass security restrictions. This vulnerability can lead to unauthorized access and potentially further exploitation such as Server-Side Template Injection (SSTI).
Affected products
- Hitachi Vantara Pentaho Business Analytics Server before 9.4.0.1 and 9.3.0.2, including 8.3.x
Timeline
- 2023-04-10: disclosed: Initial NIST analysis published
- 2024-11-21: other: Public exploit references added to CVE record
- 2025-03-03: kev added: Added to CISA Known Exploited Vulnerabilities (KEV) catalog