CVE-2022-4815

HIGH

Hitachi Vantara Pentaho Business Analytics Server <9.4.0.1-9.3.0.3 ...

Title source: llm

Description

Hitachi Vantara Pentaho Business Analytics Server versions before 9.4.0.1 and 9.3.0.3, including 8.3.x deserialize untrusted JSON data without constraining the parser to approved classes and methods. 

Scores

CVSS v3 8.0
EPSS 0.0064
EPSS Percentile 70.1%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H

Classification

CWE
CWE-502
Status published

Affected Products (3)

hitachi/vantara_pentaho < 8.3.0.25
hitachi/vantara_pentaho_business_analytics_server < 9.3.0.3
hitachi/vantara_pentaho_business_analytics_server

Timeline

Published May 24, 2023
Tracked Since Feb 18, 2026