Medium severity6.3NVD Advisory· Published Apr 3, 2023· Updated Jun 17, 2026
CVE-2022-3960
CVE-2022-3960
Description
Hitachi Vantara Pentaho Business Analytics Server prior to versions 9.4.0.1 and 9.3.0.2, including 8.3.x cannot allow a system administrator to disable scripting capabilities of the Community Dashboard Editor (CDE) plugin.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
4cpe:2.3:a:hitachi:vantara_pentaho_business_analytics_server:*:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:a:hitachi:vantara_pentaho_business_analytics_server:*:*:*:*:*:*:*:*range: <9.3.0.2
- cpe:2.3:a:hitachi:vantara_pentaho_business_analytics_server:9.4.0.0:*:*:*:*:*:*:*
<9.4.0.1 and <9.3.0.2, including 8.3.x+ 1 more
- (no CPE)range: <9.4.0.1 and <9.3.0.2, including 8.3.x
- (no CPE)range: 1.0
Patches
Vulnerability mechanics
References
1News mentions
0No linked articles in our index yet.