Hitachi Vantara Pentaho Business Analytics Server prior to versions 9.4.0.1 and 9.3.0.2, including 8.3.x allow certain web services to set property values which contain Spring templates that are interpreted downstream.
2023-04-03T18:15:07.703
2025-03-13T19:52:34.550
Analyzed
CVSSv3.1: 8.8 (HIGH)
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | hitachi | vantara_pentaho_business_analytics_server | < 9.3.0.2 | Yes |
Application | hitachi | vantara_pentaho_business_analytics_server | 9.4.0.0 | Yes |