CVE-2023-3517

HIGH

Hitachi Vantara Pentaho Data Integration & Analytics <9.5.0.1-9.3.0...

Title source: llm

Description

Hitachi Vantara Pentaho Data Integration & Analytics versions before 9.5.0.1 and 9.3.0.5, including 8.3.x does not restrict JNDI identifiers during the creation of XActions, allowing control of system level data sources.

Scores

CVSS v3 8.5
EPSS 0.0012
EPSS Percentile 31.3%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:H/A:N

Classification

CWE
CWE-99
Status published

Affected Products (1)

hitachi/pentaho_data_integration_and_analytics < 9.3.0.5

Timeline

Published Dec 12, 2023
Tracked Since Feb 18, 2026