High severity8.0NVD Advisory· Published May 24, 2023· Updated Jun 17, 2026
CVE-2022-4815
CVE-2022-4815
Description
Hitachi Vantara Pentaho Business Analytics Server versions before 9.4.0.1 and 9.3.0.3, including 8.3.x deserialize untrusted JSON data without constraining the parser to approved classes and methods.
Affected products
6cpe:2.3:a:hitachi:vantara_pentaho_business_analytics_server:*:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:a:hitachi:vantara_pentaho_business_analytics_server:*:*:*:*:*:*:*:*range: >=9.3.0.0,<=9.3.0.3
- cpe:2.3:a:hitachi:vantara_pentaho_business_analytics_server:9.4.0.0:*:*:*:*:*:*:*
<9.4.0.1, <9.3.0.3, 8.3.x+ 1 more
- (no CPE)range: <9.4.0.1, <9.3.0.3, 8.3.x
- (no CPE)range: 1.0
- Range: <9.4.0.1, <9.3.0.3, 8.3.x
Patches
Vulnerability mechanics
References
1News mentions
0No linked articles in our index yet.