CVE-2022-43769 KEV EXPLOIT
8.8
HIGH · CVSS 3.1 · EPSS 97.7% (pctl 100)
Patch first
On CISA KEV — known exploited in the wild, due 2025-03-24.
Description
Hitachi Vantara Pentaho Business Analytics Server prior to versions 9.4.0.1 and 9.3.0.2, including 8.3.x allow certain web services to set property values which contain Spring templates that are interpreted downstream.
Scoring
| CVSS | 8.8 (HIGH, v3.1) |
|---|---|
| Vector | CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
| EPSS | 97.67% — more likely to be exploited than 100% of all CVEs |
| Weakness | CWE-74 |
| On CISA KEV | yes — remediate by 2025-03-24 |
| Public exploit | yes |
| Published | 2023-04-03 |
| Last modified | 2026-06-17 |
CISA KEV
| Name | Hitachi Vantara Pentaho BA Server Special Element Injection Vulnerability |
|---|---|
| Added | 2025-03-03 |
| Due | 2025-03-24 |
| Vendor / product | Hitachi Vantara / Pentaho Business Analytics (BA) Server |
| Ransomware use | none reported |
Affected (1)
| Vendor | Product |
|---|---|
| hitachi | vantara pentaho business analytics server |
Public exploits
| Source | Title | Date |
|---|---|---|
| exploit-db | Pentaho BA Server EE 9.3.0.0-428 - Remote Code Execution (RCE) (Unauthenticated) | 2023-04-08 |
References
- http://packetstormsecurity.com/files/172296/Pentaho-Business-Server-Authentication-Bypass-SSTI-Code-Execution.html
- https://support.pentaho.com/hc/en-us/articles/14455561548301--Resolved-Pentaho-BA-Server-Failure-to-Sanitize-Special-Elements-into-a-Different-Plane-Special-Element-Injection-Versions-before-9-4-0-1-and-9-3-0-2-including-8-3-x-Impacted-CVE-2022-43769-
- http://packetstormsecurity.com/files/172296/Pentaho-Business-Server-Authentication-Bypass-SSTI-Code-Execution.html
- https://support.pentaho.com/hc/en-us/articles/14455561548301--Resolved-Pentaho-BA-Server-Failure-to-Sanitize-Special-Elements-into-a-Different-Plane-Special-Element-Injection-Versions-before-9-4-0-1-and-9-3-0-2-including-8-3-x-Impacted-CVE-2022-43769-
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2022-43769
→ the Explorer · watch your stack · NVD