Junglewise Threat Intelligence

CVE-2022-43939: Hitachi Vantara Pentaho BA Server Authorization Bypass Vulnerability

CVE-2022-43939 · Severity: critical · CVSS 9.8 · Exploited in the wild · Published 2025-03-03

Vendors: Hitachi Vantara.

Executive brief

Hitachi Vantara Pentaho Business Analytics Server uses non-canonical URL paths for authorization decisions, allowing remote attackers to bypass security restrictions. This vulnerability can lead to unauthorized access and potentially further exploitation such as Server-Side Template Injection (SSTI).

Affected products

  • Hitachi Vantara Pentaho Business Analytics Server before 9.4.0.1 and 9.3.0.2, including 8.3.x

Timeline

  • 2023-04-10: disclosed: Initial NIST analysis published
  • 2024-11-21: other: Public exploit references added to CVE record
  • 2025-03-03: kev added: Added to CISA Known Exploited Vulnerabilities (KEV) catalog

Related threats