VYPR
Unrated severityNVD Advisory· Published Apr 3, 2023· Updated Feb 11, 2025

Hitachi Vantara Pentaho Business Analytics Server - Generation of Error Message Containing Sensitive Information

CVE-2022-4769

Description

Hitachi Vantara Pentaho Business Analytics Server prior to versions 9.4.0.0 and 9.3.0.2, including 8.3.x display the target path on host when a file is uploaded with an invalid character in its name.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Hitachi Vantara Pentaho BA Server prior to 9.4.0.0 and 9.3.0.2 exposes the server path in error messages when uploading a file with an invalid character, aiding further attacks.

Vulnerability

Hitachi Vantara Pentaho Business Analytics Server versions before 9.4.0.0 and 9.3.0.2, including the 8.3.x line, generate an error message that includes the full server path when a file with an invalid character in its name is uploaded. This is a CWE-209 (Generation of Error Message Containing Sensitive Information) weakness [1].

Exploitation

An attacker with the ability to upload a file to the Pentaho BA Server can trigger the vulnerability by providing a filename containing an invalid character. No special privileges beyond file upload access are required. The server responds with an error message that discloses the absolute path of the target directory on the host filesystem [1].

Impact

Successful exploitation reveals the server’s internal path structure, which an attacker can leverage to craft more precise attacks, such as path traversal (CWE-22) attempts. The information disclosure itself does not grant code execution or data modification, but it lowers the barrier for subsequent, more severe exploits [1].

Mitigation

Hitachi Vantara has addressed the issue in Pentaho BA Server version 9.4.0.0 and in Service Pack 9.3.0.2 for the 9.3 release line. Users on older branches should upgrade to one of these fixed versions. No workaround is documented; the vendor recommends reviewing the Pentaho End-of-Life policy to ensure the deployed version is still supported [1].

AI Insight generated on May 25, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

2

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

1

News mentions

0

No linked articles in our index yet.