ZeroHour

CVE-2023-3517

CVSS 3.1
8.8 high
EPSS
<1%p49
Published
()
Modified
Description

Hitachi Vantara Pentaho Data Integration & Analytics versions before 9.5.0.1 and 9.3.0.5, including 8.3.x does not restrict JNDI identifiers during the creation of XActions, allowing control of system level data sources.

Vendors
hitachi
Products
pentaho data integration and analytics
Weakness
CWE-99
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.