Hitachi Vantara Pentaho Business Analytics Server - Improper Neutralization of Directives in Statically Saved Code ('Static Code Injection')
CVE-2022-43938
What is CVE-2022-43938?
Hitachi Vantara's Pentaho Business Analytics Server prior to versions 9.4.0.1 and 9.3.0.2, including 8.3.x, exposes a critical weakness where system administrators are unable to disable the scripting capabilities of Pentaho Reports (*.prpt) through the JVM script manager. This vulnerability can lead to static code injection risks, as unauthorized scripts may be executed, potentially compromising the integrity and security of data handled by the analytics server.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
Pentaho Business Analytics Server 1.0 < 9.3.0.2
Pentaho Business Analytics Server 9.4.0.0 < 9.4.0.1
References
EPSS Score
22% chance of being exploited in the next 30 days.
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved