CVE-2022-43938
high · 8.8Hitachi Vantara Pentaho Business Analytics Server prior to versions 9.4.0.1 and 9.3.0.2, including 8.3.x cannot allow a system administrator to disable scripting capabilities of Pentaho Reports (*.prpt) through the JVM script manager.
8.8
CVSS
26.4%
EPSS (exploit prob.)
98th
EPSS percentile
2023-04-03
Published
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Weaknesses
CWE-96CWE-94
Affected products
| Vendor | Product | Affected versions |
|---|---|---|
| hitachi | vantara_pentaho_business_analytics_server | < 9.3.0.2 |
| hitachi | vantara_pentaho_business_analytics_server | 9.4.0.0 |
Check a specific version with /api/v1/cve/match.
References
- https://support.pentaho.com/hc/en-us/articles/14454630725645--Resolved-Pentaho-BA-Server-Improper-Neutralization-of-Directives-in-Statically-Saved-Code-Static-Code-Injection-Versions-before-9-4-0-1-and-9-3-0-2-including-8-3-x-Impacted-CVE-2022-43938-
- https://support.pentaho.com/hc/en-us/articles/14454630725645--Resolved-Pentaho-BA-Server-Improper-Neutralization-of-Directives-in-Statically-Saved-Code-Static-Code-Injection-Versions-before-9-4-0-1-and-9-3-0-2-including-8-3-x-Impacted-CVE-2022-43938-
Query this programmatically:
curl https://evil-db.io/api/v1/cve/CVE-2022-43938