Hitachi.Vantara.Pentaho.BAS.Remote.Code.Injection

description-logoDescription

This indicates an attack attempt to exploit a Remote Code Injection vulnerability in Hitachi Vantara Pentaho Business Analytics Server.
The vulnerability is due to insufficient validation error when handling an crafted HTTP request. An unauthenticated remote attacker may be able to exploit this to execute remote code within the context of the target system.

affected-products-logoAffected Products

Hitachi Vantara Pentaho Business Analytics Server prior to versions 9.4.0.1
Hitachi Vantara Pentaho Business Analytics Server prior to versions 9.3.0.2
Hitachi Vantara Pentaho Business Analytics Server version 8.3.x

Impact logoImpact

System Compromise: Remote attackers can gain control of vulnerable systems.

Coverage

IPS (Regular DB)
IPS (Extended DB)

Version Updates

Date Version Detail
2023-07-10 24.596 Default_action:pass:drop
2023-06-13 24.575