ZeroHour

CVE-2022-43769

KEV PoC moderate

Spring Template Injection RCE in Hitachi Vantara Pentaho BA Server

CISA: Hitachi Vantara Pentaho BA Server Special Element Injection Vulnerability

CVSS 3.1
7.2 high
EPSS
98%p100
Published
()
KEV added
AI analysis

CVE-2022-43769 is a special element injection flaw (CWE-74/CWE-94) in Hitachi Vantara Pentaho Business Analytics (BA) Server in which certain web services accept property values containing Spring templates that are later interpreted and evaluated by the server, allowing injected template code to execute. An attacker with network access and, per the official CVSS scoring, a high-privileged account, can trigger the flaw through these web services; the published proof-of-concept chains the template injection with an authentication bypass to achieve code execution. Successful exploitation yields arbitrary code execution on the server with high impact on confidentiality, integrity, and availability. All Pentaho BA Server releases prior to 9.4.0.1 and 9.3.0.2 are affected, including the 8.3.x line. The flaw was added to CISA's Known Exploited Vulnerabilities catalog on 2025-03-03, indicating active exploitation, and EPSS puts its 30-day exploitation probability at 97.7%.

What to do: Upgrade Pentaho BA Server to 9.4.0.1, 9.3.0.2, or later; organizations still running 8.3.x must move to a fixed release as well, since no 8.3-specific fixed version is listed in the available data. Because the flaw is in CISA KEV and being actively exploited, patch urgently, restrict internet exposure of the Pentaho web services/APIs, and hunt for signs of exploitation on existing installs; federal agencies must follow BOD 22-01 guidance or discontinue use if mitigations are unavailable.

Affected
Hitachi Vantara Pentaho Business Analytics (BA) ServerAll versions prior to 9.4.0.1 and prior to 9.3.0.2, including all 8.3.x releases
Estimated exposure
moderateroughly 1,000–10,000 internet-exposed Pentaho BA Server instances, plus unquantified internal enterprise deployments — Public internet-wide scans of Pentaho servers typically enumerate only a few thousand reachable instances, while total enterprise deployments, including internal-only installations, are larger but uncounted.

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Hitachi Vantara Pentaho Business Analytics Server prior to versions 9.4.0.1 and 9.3.0.2, including 8.3.x allow certain web services to set property values which contain Spring templates that are interpreted downstream.

CISA Known Exploited Vulnerability
Affected
Hitachi Vantara Pentaho Business Analytics (BA) Server
Required action
Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
Due date
Ransomware use
Unknown
Vendors
hitachi
Products
vantara pentaho business analytics server
Weakness
CWE-74, CWE-94
Vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

In the news