CVE-2025-9122

MEDIUM

Hitachi Vantara Pentaho Data Integration & Analytics Community Dash...

Title source: llm
STIX 2.1

Description

Hitachi Vantara Pentaho Data Integration and Analytics Community Dashboard Framework prior to versions 10.2.0.4, including 9.3.0.x and 8.3.x display the full server stack trace when encountering an error within the GetCdfResource servlet.

Scores

CVSS v3 5.3
EPSS 0.0005
EPSS Percentile 15.4%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact partial

Details

CWE
CWE-209
Status published
Products (1)
Hitachi Vantara/Pentaho Data Integration and Analytics 1.0 - 10.2.0.4
Published Dec 15, 2025
Tracked Since Feb 18, 2026