Executive brief
Hitachi Vantara Pentaho Data Integration & Analytics is a platform used by businesses to manage and analyze large volumes of data. A security vulnerability exists in how the system handles database connections, which could allow an administrative user to execute unauthorized scripts on the server. This could lead to a complete takeover of the data platform, potentially exposing sensitive corporate data or disrupting business operations.
Technical details
Hitachi Vantara Pentaho Data Integration & Analytics contains a vulnerable H2 JDBC driver that allows for external script execution. The vulnerability is triggered when a user with data source administrator privileges creates a new database connection. By providing a specially crafted connection string or configuration, an attacker can leverage the H2 driver's capabilities to execute arbitrary code or scripts on the underlying host. This issue affects all versions prior to 10.2.0.7 and 11.0.0.0. Remediation requires upgrading to the patched versions which update the underlying third-party dependencies.
Affected products
- Hitachi Vantara Pentaho Data Integration & Analytics All versions before 10.2.0.7 and 11.0.0.0
Timeline
- 2026-05-13: disclosed
- 2026-05-13: advisory