Executive brief
Hitachi Vantara Pentaho Data Integration & Analytics is a platform used by businesses to prepare, integrate, and analyze large volumes of data. A security vulnerability in how the software processes data files could allow an authorized user to view sensitive files on the server or access internal network resources that should be restricted. This could lead to the unauthorized exposure of confidential corporate data or system configuration information.
Technical details
The vulnerability is an XML External Entity (XXE) injection (CWE-611) within Hitachi Vantara Pentaho Data Integration & Analytics. The root cause is the failure of certain XML parsers within the application to properly restrict or disable the resolution of external entities when processing XML-based input. An authenticated attacker with network access can exploit this by submitting a specially crafted XML document. Successful exploitation allows the attacker to read local files from the server filesystem or perform Server-Side Request Forgery (SSRF) to interact with internal services. The issue is resolved in versions 10.2.0.7 and 11.0.0.0.
Affected products
- Hitachi Vantara Pentaho Data Integration & Analytics Before 10.2.0.7, before 11.0.0.0, including 9.3.x and 8.3.x
Timeline
- 2026-05-27: advisory: Initial disclosure by Hitachi Vantara and NVD publication.