Hitachi Vantara Pentaho Data Integration & Analytics
cpe:2.3:a:hitachi:pentaho_data_integration_and_analytics:*:*:*:*:*:*:*
- < 10.2.0.6
- >= 9.3, < 9.4
- >= 8.3, < 8.4
A remote code execution vulnerability exists in Hitachi Vantara Pentaho Data Integration & Analytics versions prior to 10.2.0.6, including 9.3.x and 8.3.x. The vulnerability arises because the application does not properly restrict Groovy scripts in new PRPT reports published by users. This lack of restriction allows the insertion of arbitrary scripts, which can be executed remotely.
Exploitation of this vulnerability allows unauthorized users to execute arbitrary code on the server where Pentaho Data Integration and Analytics is running.
Users are advised to upgrade to Hitachi Vantara Pentaho Data Integration & Analytics version 10.2.0.6 or later. This vulnerability is also addressed in Pentaho Data Integration & Analytics 11.0.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.