High severity8.8CISA KEVNVD Advisory· Published Apr 3, 2023· Updated Jun 17, 2026
CVE-2022-43769
CVE-2022-43769
Description
Hitachi Vantara Pentaho Business Analytics Server prior to versions 9.4.0.1 and 9.3.0.2, including 8.3.x allow certain web services to set property values which contain Spring templates that are interpreted downstream.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
5cpe:2.3:a:hitachi:vantara_pentaho_business_analytics_server:*:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:a:hitachi:vantara_pentaho_business_analytics_server:*:*:*:*:*:*:*:*range: >=8.3.0.0,<9.3.0.2
- cpe:2.3:a:hitachi:vantara_pentaho_business_analytics_server:9.4.0.0:*:*:*:*:*:*:*
- Range: <9.4.0.1 and <9.3.0.2, including 8.3.x
<9.4.0.1 and <9.3.0.2, including 8.3.x+ 1 more
- (no CPE)range: <9.4.0.1 and <9.3.0.2, including 8.3.x
- (no CPE)range: 1.0
Patches
Vulnerability mechanics
References
3- packetstormsecurity.com/files/172296/Pentaho-Business-Server-Authentication-Bypass-SSTI-Code-Execution.htmlnvdExploit
- support.pentaho.com/hc/en-us/articles/14455561548301--Resolved-Pentaho-BA-Server-Failure-to-Sanitize-Special-Elements-into-a-Different-Plane-Special-Element-Injection-Versions-before-9-4-0-1-and-9-3-0-2-including-8-3-x-Impacted-CVE-2022-43769-nvdVendor Advisory
- www.cisa.gov/known-exploited-vulnerabilities-catalognvdUS Government Resource
News mentions
0No linked articles in our index yet.