High severity8.5NVD Advisory· Published Dec 12, 2023· Updated Jun 17, 2026
CVE-2023-3517
CVE-2023-3517
Description
Hitachi Vantara Pentaho Data Integration & Analytics versions before 9.5.0.1 and 9.3.0.5, including 8.3.x does not restrict JNDI identifiers during the creation of XActions, allowing control of system level data sources.
Affected products
3- cpe:2.3:a:hitachi:pentaho_data_integration_and_analytics:*:*:*:*:*:*:*:*Range: >=1.0,<9.3.0.5
<9.5.0.1, <9.3.0.5, 8.3.x+ 1 more
- (no CPE)range: <9.5.0.1, <9.3.0.5, 8.3.x
- (no CPE)range: 1.0
Patches
Vulnerability mechanics
References
1- support.pentaho.com/hc/en-us/articles/19668665099533nvdVendor Advisory
News mentions
0No linked articles in our index yet.