Hitachi Vantara Known Exploited Vulnerabilities

Evidence-backed KEV intelligence for Hitachi Vantara products — CISA KEV status, confidence, sensor telemetry, and virtual-patch availability.

Total KEVs

3

In CISA KEV

2

Beyond CISA KEV

1

Sensor Observed

0

Virtual Patch Available

0

Hitachi Vantara KEVs Added by Year

Loading...

3 Hitachi Vantara KEVs added all time (primary attestation date).

Attested CVEs

CVE Confidence CISA KEV Added
CVE-2021-31602

An issue was discovered in Hitachi Vantara Pentaho through 9.1 and Pentaho Business Intelligence Server through 7.x. The Security Model has...

High Not in CISA 01 Jul 2025
CVE-2022-43939

Hitachi Vantara Pentaho Business Analytics Server - Use of Non-Canonical URL Paths for Authorization Decisions

Confirmed In CISA 03 Mar 2025
CVE-2022-43769

Hitachi Vantara Pentaho Business Analytics Server - Failure to Sanitize Special Elements into a Different Plane (Special Element Injection)

Confirmed In CISA 03 Mar 2025

Common Vulnerability Classes (CWE)

  • CWE-287 — Improper Authentication 1
  • CWE-647 — Use of Non-Canonical URL Paths for Authorization Decisions 1
  • CWE-74 — Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection') 1

Browse all known exploited vulnerabilities · What is a known exploited vulnerability? · Methodology