ZeroHour

CVE-2022-43939

KEV PoC moderate

Authorization Bypass in Hitachi Vantara Pentaho Business Analytics Server

CISA: Hitachi Vantara Pentaho BA Server Authorization Bypass Vulnerability

CVSS 3.1
9.8 critical
EPSS
92%p100
Published
()
KEV added
AI analysis

Hitachi Vantara Pentaho Business Analytics (BA) Server versions before 9.4.0.1 and 9.3.0.2, including all 8.3.x releases, enforce security restrictions using non-canonical URL checks (CWE-647), so an attacker can circumvent authentication and authorization with crafted, non-canonical URL variants. The flaw is network-exploitable with no privileges or user interaction required (CVSS 3.1 score of 9.8), meaning a remote unauthenticated attacker can reach protected functionality simply by sending specially formed URLs to the server. A public proof-of-concept (published on Packet Storm) demonstrates the authentication bypass chained with server-side template injection (SSTI) to achieve code execution. Organizations running affected Pentaho BA Server versions — typically enterprises using the platform for BI reporting and analytics — are affected, particularly where the server is reachable from untrusted networks. The vulnerability was added to CISA's Known Exploited Vulnerabilities catalog on 2025-03-03, confirming exploitation in the wild, and EPSS assigns it a 92.3% probability of exploitation within 30 days (100th percentile).

What to do: Upgrade Pentaho BA Server to 9.4.0.1 or 9.3.0.2 or later; 8.3.x deployments are also affected and must move to a fixed release per Hitachi Vantara's guidance. Federal agencies must apply the required BOD 22-01 mitigations per the KEV listing (or discontinue use if mitigations are unavailable). All defenders should identify internet-exposed Pentaho instances, restrict access to trusted networks where possible, and hunt for indicators of the authentication bypass/SSTI exploitation chain.

Affected
Hitachi Vantara Pentaho Business Analytics (BA) ServerAll versions before 9.4.0.1 and before 9.3.0.2, including all 8.3.x releases
Estimated exposure
moderate≈1,000–10,000 deployments (estimate; no authoritative install count available) — Pentaho BA Server is enterprise BI software typically deployed on-premises once per customer organization rather than at internet scale, and public internet-exposed instances appear to number only in the low thousands, though total…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Hitachi Vantara Pentaho Business Analytics Server versions before 9.4.0.1 and 9.3.0.2, including 8.3.x contain security restrictions using non-canonical URLs which can be circumvented.

CISA Known Exploited Vulnerability
Affected
Hitachi Vantara Pentaho Business Analytics (BA) Server
Required action
Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
Due date
Ransomware use
Unknown
Vendors
hitachi
Products
vantara pentaho business analytics server
Weakness
CWE-647
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news