CVE-2022-4815
HIGHHitachi Vantara Pentaho Business Analytics Server <9.4.0.1-9.3.0.3 ...
Title source: llmDescription
Hitachi Vantara Pentaho Business Analytics Server versions before 9.4.0.1 and 9.3.0.3, including 8.3.x deserialize untrusted JSON data without constraining the parser to approved classes and methods.
Scores
CVSS v3
8.0
EPSS
0.0064
EPSS Percentile
70.1%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H
Classification
CWE
CWE-502
Status
published
Affected Products (3)
hitachi/vantara_pentaho
< 8.3.0.25
hitachi/vantara_pentaho_business_analytics_server
< 9.3.0.3
hitachi/vantara_pentaho_business_analytics_server
Timeline
Published
May 24, 2023
Tracked Since
Feb 18, 2026