CVE-2022-43773
high · 8.8Hitachi Vantara Pentaho Business Analytics Server prior to versions 9.4.0.1 and 9.3.0.2, including 8.3.x is installed with a sample HSQLDB data source configured with stored procedures enabled.
8.8
CVSS
22.2%
EPSS (exploit prob.)
98th
EPSS percentile
2023-04-03
Published
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Weaknesses
CWE-732
Affected products
| Vendor | Product | Affected versions |
|---|---|---|
| hitachi | vantara_pentaho_business_analytics_server | >= 8.3.0.0, < 9.3.0.2 |
| hitachi | vantara_pentaho_business_analytics_server | 9.4.0.0 |
Check a specific version with /api/v1/cve/match.
References
- https://support.pentaho.com/hc/en-us/articles/14453135249165--Resolved-Pentaho-BA-Server-Incorrect-Permission-Assignment-for-Critical-Resource-Versions-before-9-4-0-1-and-9-3-0-2-including-8-3-x-Impacted-CVE-2022-43773-
- https://support.pentaho.com/hc/en-us/articles/14453135249165--Resolved-Pentaho-BA-Server-Incorrect-Permission-Assignment-for-Critical-Resource-Versions-before-9-4-0-1-and-9-3-0-2-including-8-3-x-Impacted-CVE-2022-43773-
Query this programmatically:
curl https://evil-db.io/api/v1/cve/CVE-2022-43773