CVE-2023-3517
HIGHHitachi Vantara Pentaho Data Integration & Analytics <9.5.0.1-9.3.0...
Title source: llmDescription
Hitachi Vantara Pentaho Data Integration & Analytics versions before 9.5.0.1 and 9.3.0.5, including 8.3.x does not restrict JNDI identifiers during the creation of XActions, allowing control of system level data sources.
Scores
CVSS v3
8.5
EPSS
0.0012
EPSS Percentile
31.3%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:H/A:N
Classification
CWE
CWE-99
Status
published
Affected Products (1)
hitachi/pentaho_data_integration_and_analytics
< 9.3.0.5
Timeline
Published
Dec 12, 2023
Tracked Since
Feb 18, 2026