CVE-2022-43939
KEV PoC moderateAuthorization Bypass in Hitachi Vantara Pentaho Business Analytics Server
CISA: Hitachi Vantara Pentaho BA Server Authorization Bypass Vulnerability
Hitachi Vantara Pentaho Business Analytics (BA) Server versions before 9.4.0.1 and 9.3.0.2, including all 8.3.x releases, enforce security restrictions using non-canonical URL checks (CWE-647), so an attacker can circumvent authentication and authorization with crafted, non-canonical URL variants. The flaw is network-exploitable with no privileges or user interaction required (CVSS 3.1 score of 9.8), meaning a remote unauthenticated attacker can reach protected functionality simply by sending specially formed URLs to the server. A public proof-of-concept (published on Packet Storm) demonstrates the authentication bypass chained with server-side template injection (SSTI) to achieve code execution. Organizations running affected Pentaho BA Server versions — typically enterprises using the platform for BI reporting and analytics — are affected, particularly where the server is reachable from untrusted networks. The vulnerability was added to CISA's Known Exploited Vulnerabilities catalog on 2025-03-03, confirming exploitation in the wild, and EPSS assigns it a 92.3% probability of exploitation within 30 days (100th percentile).
What to do: Upgrade Pentaho BA Server to 9.4.0.1 or 9.3.0.2 or later; 8.3.x deployments are also affected and must move to a fixed release per Hitachi Vantara's guidance. Federal agencies must apply the required BOD 22-01 mitigations per the KEV listing (or discontinue use if mitigations are unavailable). All defenders should identify internet-exposed Pentaho instances, restrict access to trusted networks where possible, and hunt for indicators of the authentication bypass/SSTI exploitation chain.
| Hitachi Vantara Pentaho Business Analytics (BA) Server | All versions before 9.4.0.1 and before 9.3.0.2, including all 8.3.x releases |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Hitachi Vantara Pentaho Business Analytics Server versions before 9.4.0.1 and 9.3.0.2, including 8.3.x contain security restrictions using non-canonical URLs which can be circumvented.
- Affected
- Hitachi Vantara Pentaho Business Analytics (BA) Server
- Required action
- Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
- Due date
- Ransomware use
- Unknown
- Vendors
- hitachi
- Products
- vantara pentaho business analytics server
- Weakness
- CWE-647
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H