{
    "id": "CVE-2022-43769",
    "published": "2023-04-03 18:15:07",
    "last_modified": "2026-06-17 05:07:17",
    "cvss_score": "8.8",
    "cvss_severity": "HIGH",
    "cvss_version": "3.1",
    "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
    "cwe": "CWE-74",
    "description": "Hitachi Vantara Pentaho Business Analytics Server prior to versions 9.4.0.1 and 9.3.0.2, including 8.3.x allow certain web services to set property values which contain Spring templates that are interpreted downstream.",
    "epss_score": "0.97670",
    "epss_percentile": "0.99902",
    "kev": 1,
    "kev_due": "2025-03-24",
    "has_exploit": 1,
    "updated_at": "2026-09-26 18:31:28",
    "priority": {
        "rank": 1,
        "label": "Patch first",
        "why": "On CISA KEV — known exploited in the wild, due 2025-03-24."
    },
    "products": [
        {
            "vendor": "hitachi",
            "product": "vantara_pentaho_business_analytics_server"
        }
    ],
    "kev_detail": {
        "cve_id": "CVE-2022-43769",
        "date_added": "2025-03-03",
        "due_date": "2025-03-24",
        "vendor": "Hitachi Vantara",
        "product": "Pentaho Business Analytics (BA) Server",
        "name": "Hitachi Vantara Pentaho BA Server Special Element Injection Vulnerability",
        "ransomware": 0
    },
    "exploits": [
        {
            "source": "exploit-db",
            "ref_id": "51350",
            "title": "Pentaho BA Server EE 9.3.0.0-428 - Remote Code Execution (RCE) (Unauthenticated)",
            "date": "2023-04-08",
            "url": "https://www.exploit-db.com/exploits/51350"
        }
    ],
    "refs_list": [
        "http://packetstormsecurity.com/files/172296/Pentaho-Business-Server-Authentication-Bypass-SSTI-Code-Execution.html",
        "https://support.pentaho.com/hc/en-us/articles/14455561548301--Resolved-Pentaho-BA-Server-Failure-to-Sanitize-Special-Elements-into-a-Different-Plane-Special-Element-Injection-Versions-before-9-4-0-1-and-9-3-0-2-including-8-3-x-Impacted-CVE-2022-43769-",
        "http://packetstormsecurity.com/files/172296/Pentaho-Business-Server-Authentication-Bypass-SSTI-Code-Execution.html",
        "https://support.pentaho.com/hc/en-us/articles/14455561548301--Resolved-Pentaho-BA-Server-Failure-to-Sanitize-Special-Elements-into-a-Different-Plane-Special-Element-Injection-Versions-before-9-4-0-1-and-9-3-0-2-including-8-3-x-Impacted-CVE-2022-43769-",
        "https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2022-43769"
    ]
}