CVE-2022-43769
KEV PoC moderateSpring Template Injection RCE in Hitachi Vantara Pentaho BA Server
CISA: Hitachi Vantara Pentaho BA Server Special Element Injection Vulnerability
CVE-2022-43769 is a special element injection flaw (CWE-74/CWE-94) in Hitachi Vantara Pentaho Business Analytics (BA) Server in which certain web services accept property values containing Spring templates that are later interpreted and evaluated by the server, allowing injected template code to execute. An attacker with network access and, per the official CVSS scoring, a high-privileged account, can trigger the flaw through these web services; the published proof-of-concept chains the template injection with an authentication bypass to achieve code execution. Successful exploitation yields arbitrary code execution on the server with high impact on confidentiality, integrity, and availability. All Pentaho BA Server releases prior to 9.4.0.1 and 9.3.0.2 are affected, including the 8.3.x line. The flaw was added to CISA's Known Exploited Vulnerabilities catalog on 2025-03-03, indicating active exploitation, and EPSS puts its 30-day exploitation probability at 97.7%.
What to do: Upgrade Pentaho BA Server to 9.4.0.1, 9.3.0.2, or later; organizations still running 8.3.x must move to a fixed release as well, since no 8.3-specific fixed version is listed in the available data. Because the flaw is in CISA KEV and being actively exploited, patch urgently, restrict internet exposure of the Pentaho web services/APIs, and hunt for signs of exploitation on existing installs; federal agencies must follow BOD 22-01 guidance or discontinue use if mitigations are unavailable.
| Hitachi Vantara Pentaho Business Analytics (BA) Server | All versions prior to 9.4.0.1 and prior to 9.3.0.2, including all 8.3.x releases |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Hitachi Vantara Pentaho Business Analytics Server prior to versions 9.4.0.1 and 9.3.0.2, including 8.3.x allow certain web services to set property values which contain Spring templates that are interpreted downstream.
- Affected
- Hitachi Vantara Pentaho Business Analytics (BA) Server
- Required action
- Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
- Due date
- Ransomware use
- Unknown
- Vendors
- hitachi
- Products
- vantara pentaho business analytics server
- Weakness
- CWE-74, CWE-94
- Vector
- CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H