Hitachi Vantara Pentaho Business Analytics Server - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
Description
Hitachi Vantara Pentaho Business Analytics Server prior to versions 9.4.0.1 and 9.3.0.2, including 8.3.x allow a malicious URL to inject content into the Pentaho User Console through session variables.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Hitachi Vantara Pentaho BA Server before 9.4.0.1 and 9.3.0.2 allows reflected XSS via a malicious URL injecting into session variables.
Vulnerability
The vulnerability is a cross-site scripting (XSS) flaw in Hitachi Vantara Pentaho Business Analytics Server. It stems from improper neutralization of user-controllable input before it is placed in output used as a web page served to other users (CWE-79) [1]. Specifically, a malicious URL can inject content into the Pentaho User Console through session variables. Affected versions include all versions prior to 9.4.0.1 and 9.3.0.2, including the 8.3.x series.
Exploitation
An attacker can craft a malicious URL containing the injected payload and trick a victim into clicking it via social engineering or by embedding the URL in other content [1]. No special privileges or network position are required; the attacker only needs to convince a user to visit the crafted link.
Impact
Successful exploitation allows the attacker to execute arbitrary JavaScript in the context of the victim's browser [1]. This can lead to theft of sensitive information such as cookies (including session tokens), performing actions on behalf of the victim, and defacement. If the victim has administrative privileges, the attacker could gain control over the entire Pentaho instance.
Mitigation
Hitachi Vantara recommends upgrading to Pentaho version 9.4.0.1 or 9.3.0.2, which contain the fix for this vulnerability [1]. Users on unsupported versions should update to a supported release. No workaround is provided.
AI Insight generated on May 25, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected products
2- Range: <9.4.0.1 & <9.3.0.2
- Range: 1.0
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
1News mentions
0No linked articles in our index yet.