PT-2025-16913 · Hitachi Vantara · Hitachi Vantara Pentaho Data Integration & Analytics

Published

2025-04-16

·

Updated

2025-04-18

·

CVE-2025-0756

CVSS v3.1

9.1

Critical

VectorAV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Hitachi Vantara Pentaho Data Integration & Analytics versions prior to 10.2.0.2
Description The product receives input from an upstream component but does not restrict or incorrectly restricts the input before it is used as an identifier for a resource that may be outside the intended sphere of control. This could allow an attacker to gain access to or modify sensitive data or system resources, potentially leading to remote code execution by unauthorized users.
Recommendations For versions prior to 10.2.0.2, update to version 10.2.0.2 or later to resolve the issue. As a temporary workaround, consider restricting access to JNDI identifiers during the creation of platform data sources to minimize the risk of exploitation.

Fix

RCE

Weakness Enumeration

Related Identifiers

CVE-2025-0756

Affected Products

Hitachi Vantara Pentaho Data Integration & Analytics