Skip to content
logo logoSelf Service
Sign In Sign Up
  • Home
  • Knowledgebase
Back

Hitachi Vantara Pentaho BA Server Vulnerabilities (CVE-2022-43769 and CVE-2022-43939)

Updated 03/05/2025 02:29:46 PM by Ddevera
  • PDF
  • Print
  • Share
    • Facebook
  • Copy To Clipboard
  • Collapse All Expand All

Issue / Objective

Priority: Low
Status: Completed
 
First Published: 5 March 2025 
Advisory Version: 1.0
 
References: CVE-2022-43939, CVE-2022-43769

 

A recently published bulletin from the U.S. Cybersecurity and Infrastructure Security Agency (CISA) notified of two security flaws affecting older versions of Hitachi Vantara Pentaho Business Analytics Server.
These two issues relate to older versions of our analytics software and have long since been identified and addressed with fixes. Please refer to the following notifications for more information:

  • CVE-2022-43939: (Resolved) Pentaho BA Server - Use of Non-Canonical URL Paths for Authorization Decisions
  • CVE-2022-43769: (Resolved) Pentaho BA Server - Failure to Sanitize Special Elements into a Different Plane (Special Element Injection)

 

If any of the information presented above remains unclear, please contact Pentaho Support or your authorized service and support provider.

The information contained herein is for informational purposes only. It is not intended as a guaranty or warranty about Hitachi Vantara’s products, including any guaranty or warranty that any product cannot be exploited by third parties. All product warranties and obligations to a customer must be specified in a mutually acceptable and executed contract between the parties.

Keywords: Pentaho CVE-2022-437 CVE-2022-43939

Related Solutions

  • Hitachi Vantara Security Advisories - Index Page
  • Cisco NX-OS CLI Vulnerability
  • Warning Regarding Use of End-of-Life (EOL) Versions of Node.js
  • "Spring4Shell" - RCE Vulnerabilities in Spring Framework and Spring Cloud Function
  • Specific PHP Versions Vulnerability May Allow Malicious User Execution
Solution ID
250305111139973
Last Modified Date
03/05/2025 02:29:46 PM
Taxonomy
  • Security Advisories > Advisories
Collections
  • Guest (Public)

Solution to Copy:

Copy to Clipboard

Failed to download PDF file.

Problem creating pdf file for the solution: 250305111139973
Close

Acknowledged.

Thank you for acknowledging that you have read and understood this solution.

Failure.

Unable to acknowlege. An error occurred.
Knowledge
  • Knowledgebase
Helpful Links
  • Community
  • Product Documentation
Upland RightAnswers | Self Service - 2024R2
© Sat Jun 28 05:58:23 EDT 2025 Upland Software, Inc. All Rights Reserved