CVE-2022-4815
—CVSS 3.1
8.8 high
EPSS
<1%p48
Published
()
Modified
Description
Hitachi Vantara Pentaho Business Analytics Server versions before 9.4.0.1 and 9.3.0.3, including 8.3.x deserialize untrusted JSON data without constraining the parser to approved classes and methods.
- Vendors
- hitachi
- Products
- vantara pentaho, vantara pentaho business analytics server
- Weakness
- CWE-502
- Vector
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.