CVE-2022-3695: Hitachivantara Pentaho Business Analytics
Medium severity, CVSS 6.1. EPSS: 0.4% chance of exploitation in the next 30 days.
Hitachi Vantara Pentaho Business Analytics Server prior to versions 9.3.0.0, 9.2.0.4 and 8.3.0.27 allow a malicious URL to inject content into a dashboard when the CDE plugin is present.
Affected products
- Hitachivantara Pentaho Business Analytics: before 8.3.0.27 (fixed in 8.3.0.27); from 9.2.0.0, before 9.2.0.4 (fixed in 9.2.0.4)
Published 2023-04-11. Last modified 2026-06-17.