Information Disclosure in Hitachi Vantara Pentaho Data Integration and Analytics
CVE-2025-9122

5.3MEDIUM

Key Information:

Vendor

Hitachi

Vendor
CVE Published:
15 December 2025

What is CVE-2025-9122?

The Hitachi Vantara Pentaho Data Integration and Analytics Community Dashboard Framework prior to version 10.2.0.4 poses an information disclosure risk by exposing the complete server stack trace when an error occurs within the GetCdfResource servlet. This flaw can potentially allow attackers to gain insights into the internal functioning of the server and exploit other vulnerabilities within the system. Implementing updates to versions 10.2.0.4 and later is essential to safeguard against this exposure.

Affected Version(s)

Pentaho Data Integration and Analytics 1.0 < 10.2.0.4

References

CVSS V3.1

Score:
5.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Hitachi Group Member
.
CVE-2025-9122 : Information Disclosure in Hitachi Vantara Pentaho Data Integration and Analytics