KEVIntel
8.6
CVSS
High

CVE-2022-43939

PUBLISHED

Hitachi Vantara Pentaho Business Analytics Server - Use of Non-Canonical URL Paths for Authorization Decisions

Exploited in the wild Remote Low complexity No user interaction
Vendor
Hitachi Vantara
Product
Pentaho Business Analytics Server
Published
Apr 03, 2023
EPSS

Description

Hitachi Vantara Pentaho Business Analytics Server versions before 9.4.0.1 and 9.3.0.2, including 8.3.x contain security restrictions using non-canonical URLs which can be circumvented.

cisa nuclei_scanner metasploit nessus_scanner

CVSS scores

CVSS v3.1 8.6 High

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H

Exploitation status

Exploited in the wild

Recorded 2025-03-03 00:00:00 UTC · Source

SSVC decision points

Exploitation
active
Automatable
Yes
Technical impact
partial

Known exploited vulnerability sources

Catalogues that list this CVE as a known exploited vulnerability.

Source Added
CISA Mar 03, 2025

Potential proof of concepts

These PoCs are unverified and could contain malware. Use at your own risk.

pentaho_business_server_authbypass_and_ssti

metasploit · Created Unknown

Metasploit module for CVE-2022-43939

Timeline

  • CVE ID Reserved

  • CVE Published to Public

  • Added to KEVIntel

  • Detected by Metasploit

  • Detected by Nuclei