PT-2023-2236 · Hitachi Vantara · Hitachi Vantara Pentaho Business Analytics Server

Published

2023-04-03

·

Updated

2023-04-12

·

CVE-2022-43773

CVSS v2.0

9.0

High

VectorAV:N/AC:L/Au:S/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Hitachi Vantara Pentaho Business Analytics Server versions prior to 9.4.0.1 and 9.3.0.2, including 8.3.x
Description The issue is related to errors in permission assignment for files, which can allow a remote attacker to execute arbitrary code. The server is installed with a sample HSQLDB data source configured with stored procedures enabled.
Recommendations For versions prior to 9.4.0.1, update to version 9.4.0.1 or later. For versions prior to 9.3.0.2, update to version 9.3.0.2 or later. For version 8.3.x, consider upgrading to a newer version that is not affected by this issue, such as version 9.3.0.2 or later.

Fix

Incorrect Permission

Weakness Enumeration

Related Identifiers

BDU:2023-01991
CVE-2022-43773

Affected Products

Hitachi Vantara Pentaho Business Analytics Server