Hitachi Vantara Pentaho Business Analytics Server是日本日立制作所(Hitachi)公司的一个现代数据混合、集成和业务分析平台。 Hitachi Vantara Pentaho Business Analytics Server 存在代码注入漏洞,该漏洞源于允许某些 Web 服务设置包含下游解释的 Spring 模板的属性值。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
10-question deep dive: root cause, exploitation, mitigation, urgency. Read summary free, full version requires login.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Hitachi Vantara | Pentaho Business Analytics Server | 1.0 ~ 9.3.0.2 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|---|---|---|
| 1 | Hitachi Pentaho Business Analytics Server prior to versions 9.4.0.1 and 9.3.0.2, including 8.3.x, is susceptible to remote code execution via server-side template injection. Certain web services can set property values which contain Spring templates that are interpreted downstream, thereby potentially enabling an attacker to execute malware, obtain sensitive information, modify data, and/or perform unauthorized operations without entering necessary credentials. | https://github.com/projectdiscovery/nuclei-templates/blob/main/http/cves/2022/CVE-2022-43769.yaml | POC Details |
No public POC found.
Login to generate AI POC| CVE-2022-43773 | 8.8 HIGH | Hitachi Vantara Pentaho Business Analytics Server - Incorrect Permission Assignment for Cr |
| CVE-2022-43938 | 8.8 HIGH | Hitachi Vantara Pentaho Business Analytics Server - Improper Neutralization of Directives |
| CVE-2022-43939 | 8.6 HIGH | Hitachi Vantara Pentaho Business Analytics Server - Use of Non-Canonical URL Paths for Aut |
| CVE-2022-43771 | 6.5 MEDIUM | Hitachi Vantara Pentaho Business Analytics Server - Improper Limitation of a Pathname to a |
| CVE-2022-3960 | 6.3 MEDIUM | Hitachi Vantara Pentaho Business Analytics Server - Improper Neutralization of Directives |
| CVE-2022-4771 | 5.4 MEDIUM | Hitachi Vantara Pentaho Business Analytics Server - Improper Neutralization of Input Durin |
| CVE-2022-4769 | 4.3 MEDIUM | Hitachi Vantara Pentaho Business Analytics Server - Generation of Error Message Containing |
| CVE-2022-4770 | 4.3 MEDIUM | Hitachi Vantara Pentaho Business Analytics Server - Generation of Error Message Containing |
No comments yet