Hitachi Vantara Pentaho Data Integration & Analytics Path Traversal Vulnerability

Vulnerability

A path traversal vulnerability has been identified in Hitachi Vantara Pentaho Data Integration & Analytics versions prior to 10.2.0.2, including 9.3.x and 8.3.x. The issue arises because the product fails to properly sanitize user input used as file paths through the CGG Draw API. This lack of input validation allows attackers to manipulate the file path and traverse the file system, accessing files or directories outside of the intended restricted directory.

Impact

Exploitation of this vulnerability allows for unauthorized file system traversal, enabling access to files or directories outside of the restricted directory.

Remediation

Users can upgrade to Hitachi Vantara Pentaho Data Integration & Analytics version 10.2.0.2 or later to address this vulnerability.

Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM

Vulnerability Rating

Custom Algorithm
spread
3.1
impact
0.8
exploitability
4.5
remediation
0.0
relevance
0.0
threat
0.0
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.