peter bassill · operator
$ cve CVE-2022-43769 JSON

CVE-2022-43769 KEV EXPLOIT

8.8
HIGH · CVSS 3.1 · EPSS 97.7% (pctl 100)

Patch first

On CISA KEV — known exploited in the wild, due 2025-03-24.

Description

Hitachi Vantara Pentaho Business Analytics Server prior to versions 9.4.0.1 and 9.3.0.2, including 8.3.x allow certain web services to set property values which contain Spring templates that are interpreted downstream.

Scoring

CVSS8.8 (HIGH, v3.1)
VectorCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
EPSS97.67% — more likely to be exploited than 100% of all CVEs
WeaknessCWE-74
On CISA KEVyes — remediate by 2025-03-24
Public exploityes
Published2023-04-03
Last modified2026-06-17

CISA KEV

NameHitachi Vantara Pentaho BA Server Special Element Injection Vulnerability
Added2025-03-03
Due2025-03-24
Vendor / productHitachi Vantara / Pentaho Business Analytics (BA) Server
Ransomware usenone reported

Affected (1)

VendorProduct
hitachivantara pentaho business analytics server

Public exploits

References

→ the Explorer  ·  watch your stack  ·  NVD