PT-2023-14316 · Hitachi Vantara · Pentaho Business Analytics Server

Published

2023-04-11

·

Updated

2023-04-20

·

CVE-2022-43770

CVSS v3.1

8.1

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H
Name of the Vulnerable Software and Affected Versions Hitachi Vantara Pentaho Business Analytics Server versions before 9.3.0.0 Hitachi Vantara Pentaho Business Analytics Server versions before 9.2.0.4 Hitachi Vantara Pentaho Business Analytics Server versions before 8.3.0.27
Description The issue is related to an authorization check in the dashboard editor plugin API, which is not performed correctly.
Recommendations For versions before 9.3.0.0, update to version 9.3.0.0 or later. For versions before 9.2.0.4, update to version 9.2.0.4 or later. For versions before 8.3.0.27, update to version 8.3.0.27 or later.

Fix

Incorrect Authorization

Weakness Enumeration

Related Identifiers

CVE-2022-43770

Affected Products

Pentaho Business Analytics Server