Vulnerabilities (CVE)

Filtered by vendor Hitachi Subscribe
Filtered by product Vantara Pentaho Business Analytics Server
Total 4 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2023-1158 1 Hitachi 2 Vantara Pentaho, Vantara Pentaho Business Analytics Server 2024-02-04 N/A 4.3 MEDIUM
Hitachi Vantara Pentaho Business Analytics Server versions before 9.4.0.1 and 9.3.0.3, including 8.3.x expose dashboard prompts to users who are not part of the authorization list. 
CVE-2022-43939 1 Hitachi 1 Vantara Pentaho Business Analytics Server 2024-02-04 N/A 9.8 CRITICAL
Hitachi Vantara Pentaho Business Analytics Server versions before 9.4.0.1 and 9.3.0.2, including 8.3.x contain security restrictions using non-canonical URLs which can be circumvented. 
CVE-2022-43769 1 Hitachi 1 Vantara Pentaho Business Analytics Server 2024-02-04 N/A 7.2 HIGH
Hitachi Vantara Pentaho Business Analytics Server prior to versions 9.4.0.1 and 9.3.0.2, including 8.3.x allow certain web services to set property values which contain Spring templates that are interpreted downstream. 
CVE-2022-4815 1 Hitachi 2 Vantara Pentaho, Vantara Pentaho Business Analytics Server 2024-02-04 N/A 8.8 HIGH
Hitachi Vantara Pentaho Business Analytics Server versions before 9.4.0.1 and 9.3.0.3, including 8.3.x deserialize untrusted JSON data without constraining the parser to approved classes and methods.