Hitachi Vantara Pentaho Data Integration & Analytics
cpe:2.3:a:hitachi:pentaho_data_integration_and_analytics:*:*:*:*:*:*:*
- < 10.2.0.0
- < 9.3.0.9
- ~8.3
A vulnerability exists in Hitachi Vantara Pentaho Data Integration & Analytics versions prior to 10.2.0.0 and 9.3.0.9, including 8.3.x. The issue arises from improper validation of JNDI identifiers when creating Community Dashboards, allowing unauthorized control over system-level data sources. This could enable access to or modification of sensitive data or system resources, potentially leading to remote code execution by unauthorized users.
Exploitation of this vulnerability could allow unauthorized users to access or modify sensitive data and system resources, including protected files and directories containing configuration details and other sensitive information. Such access could facilitate remote code execution.
Users can upgrade to Hitachi Vantara Pentaho Data Integration & Analytics version 10.2.0.0 or 9.3.0.9 to address this vulnerability.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.