2022-10-26 13:00:32 +00:00
{
2023-04-03 18:00:35 +00:00
"data_version" : "4.0" ,
2022-10-26 13:00:32 +00:00
"data_type" : "CVE" ,
"data_format" : "MITRE" ,
"CVE_data_meta" : {
"ID" : "CVE-2022-43769" ,
2023-04-03 18:00:35 +00:00
"ASSIGNER" : "security.vulnerabilities@hitachivantara.com" ,
"STATE" : "PUBLIC"
2022-10-26 13:00:32 +00:00
} ,
"description" : {
"description_data" : [
{
"lang" : "eng" ,
2023-05-11 18:00:35 +00:00
"value" : "\nHitachi Vantara Pentaho Business Analytics Server prior to versions 9.4.0.1 and 9.3.0.2, including 8.3.x allow certain web services to set property values which contain Spring templates that are interpreted downstream.\u00a0\n\n"
2023-04-03 18:00:35 +00:00
}
]
} ,
"problemtype" : {
"problemtype_data" : [
{
"description" : [
{
"lang" : "eng" ,
"value" : "CWE-74 Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')" ,
"cweId" : "CWE-74"
}
]
}
]
} ,
"affects" : {
"vendor" : {
"vendor_data" : [
{
"vendor_name" : "Hitachi Vantara" ,
"product" : {
"product_data" : [
{
"product_name" : "Pentaho Business Analytics Server" ,
"version" : {
"version_data" : [
{
"version_affected" : "<" ,
"version_name" : "1.0" ,
"version_value" : "9.3.0.2"
} ,
{
"version_affected" : "<" ,
"version_name" : "9.4.0.0" ,
"version_value" : "9.4.0.1"
}
]
}
}
]
}
}
]
}
} ,
"references" : {
"reference_data" : [
{
"url" : "https://support.pentaho.com/hc/en-us/articles/14455561548301--Resolved-Pentaho-BA-Server-Failure-to-Sanitize-Special-Elements-into-a-Different-Plane-Special-Element-Injection-Versions-before-9-4-0-1-and-9-3-0-2-including-8-3-x-Impacted-CVE-2022-43769-" ,
"refsource" : "MISC" ,
"name" : "https://support.pentaho.com/hc/en-us/articles/14455561548301--Resolved-Pentaho-BA-Server-Failure-to-Sanitize-Special-Elements-into-a-Different-Plane-Special-Element-Injection-Versions-before-9-4-0-1-and-9-3-0-2-including-8-3-x-Impacted-CVE-2022-43769-"
2023-05-11 18:00:35 +00:00
} ,
{
"url" : "http://packetstormsecurity.com/files/172296/Pentaho-Business-Server-Authentication-Bypass-SSTI-Code-Execution.html" ,
"refsource" : "MISC" ,
"name" : "http://packetstormsecurity.com/files/172296/Pentaho-Business-Server-Authentication-Bypass-SSTI-Code-Execution.html"
2023-04-03 18:00:35 +00:00
}
]
} ,
"generator" : {
"engine" : "Vulnogram 0.1.0-dev"
} ,
"source" : {
"discovery" : "EXTERNAL"
} ,
"credits" : [
{
"lang" : "en" ,
"value" : "Harry Withington, Aura Information Security"
}
] ,
"impact" : {
"cvss" : [
{
"attackComplexity" : "LOW" ,
"attackVector" : "NETWORK" ,
"availabilityImpact" : "HIGH" ,
"baseScore" : 8.8 ,
"baseSeverity" : "HIGH" ,
"confidentialityImpact" : "HIGH" ,
"integrityImpact" : "HIGH" ,
"privilegesRequired" : "LOW" ,
"scope" : "UNCHANGED" ,
"userInteraction" : "NONE" ,
"vectorString" : "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" ,
"version" : "3.1"
2022-10-26 13:00:32 +00:00
}
]
}
}