Information Disclosure in Hitachi Vantara Pentaho Data Integration and Analytics
CVE-2025-9122
5.3MEDIUM
Key Information:
- Vendor
Hitachi
- Vendor
- CVE Published:
- 15 December 2025
What is CVE-2025-9122?
The Hitachi Vantara Pentaho Data Integration and Analytics Community Dashboard Framework prior to version 10.2.0.4 poses an information disclosure risk by exposing the complete server stack trace when an error occurs within the GetCdfResource servlet. This flaw can potentially allow attackers to gain insights into the internal functioning of the server and exploit other vulnerabilities within the system. Implementing updates to versions 10.2.0.4 and later is essential to safeguard against this exposure.
Affected Version(s)
Pentaho Data Integration and Analytics 1.0 < 10.2.0.4
References
CVSS V3.1
Score:
5.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Hitachi Group Member