CVE-2022-43939 KEV EXPLOIT
8.6
HIGH · CVSS 3.1 · EPSS 92.3% (pctl 100)
Patch first
On CISA KEV — known exploited in the wild, due 2025-03-24.
Description
Hitachi Vantara Pentaho Business Analytics Server versions before 9.4.0.1 and 9.3.0.2, including 8.3.x contain security restrictions using non-canonical URLs which can be circumvented.
Scoring
| CVSS | 8.6 (HIGH, v3.1) |
|---|---|
| Vector | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H |
| EPSS | 92.27% — more likely to be exploited than 100% of all CVEs |
| Weakness | CWE-647 |
| On CISA KEV | yes — remediate by 2025-03-24 |
| Public exploit | yes |
| Published | 2023-04-03 |
| Last modified | 2026-06-17 |
CISA KEV
| Name | Hitachi Vantara Pentaho BA Server Authorization Bypass Vulnerability |
|---|---|
| Added | 2025-03-03 |
| Due | 2025-03-24 |
| Vendor / product | Hitachi Vantara / Pentaho Business Analytics (BA) Server |
| Ransomware use | none reported |
Affected (1)
| Vendor | Product |
|---|---|
| hitachi | vantara pentaho business analytics server |
Public exploits
| Source | Title | Date |
|---|---|---|
| exploit-db | Pentaho BA Server EE 9.3.0.0-428 - Remote Code Execution (RCE) (Unauthenticated) | 2023-04-08 |
References
- http://packetstormsecurity.com/files/172296/Pentaho-Business-Server-Authentication-Bypass-SSTI-Code-Execution.html
- https://support.pentaho.com/hc/en-us/articles/14455394120333--Resolved-Pentaho-BA-Server-Use-of-Non-Canonical-URL-Paths-for-Authorization-Decisions-Versions-before-9-4-0-1-and-9-3-0-2-including-8-3-x-Impacted-CVE-2022-43939-
- http://packetstormsecurity.com/files/172296/Pentaho-Business-Server-Authentication-Bypass-SSTI-Code-Execution.html
- https://support.pentaho.com/hc/en-us/articles/14455394120333--Resolved-Pentaho-BA-Server-Use-of-Non-Canonical-URL-Paths-for-Authorization-Decisions-Versions-before-9-4-0-1-and-9-3-0-2-including-8-3-x-Impacted-CVE-2022-43939-
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2022-43939
→ the Explorer · watch your stack · NVD