PT-2023-2235 · Hitachi Vantara · Hitachi Vantara Pentaho Business Analytics Server

CVE-2022-4770

·

Publicado

2023-04-03

·

Atualizado

2023-04-10

CVSS v3.1

4.3

Média

VetorAV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions Hitachi Vantara Pentaho Business Analytics Server versions prior to 9.4.0.0 and 9.3.0.2, including 8.3.x
Description The issue is related to the error handling mechanism in Hitachi Vantara Pentaho Business Analytics Server, which displays the full parametrized SQL query in an error message when an invalid character is used within a Pentaho Report (*.prpt). This can allow a remote attacker to gain unauthorized access to protected information.
Recommendations For versions prior to 9.4.0.0, update to version 9.4.0.0 or later. For versions prior to 9.3.0.2, update to version 9.3.0.2 or later. As a temporary workaround, consider restricting access to Pentaho Reports (*.prpt) to minimize the risk of exploitation.

Correção

Generation of Error Message Containing Sensitive Information

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2023-01990
CVE-2022-4770

Produtos afetados

Hitachi Vantara Pentaho Business Analytics Server