CVE-2022-43769: Hitachi Vantara Pentaho BA Server Special Element Injection Vulnerability

High severity, CVSS 7.2. Actively exploited: in CISA KEV since 2025-03-03. EPSS: 97.7% chance of exploitation in the next 30 days.

Hitachi Vantara Pentaho Business Analytics Server prior to versions 9.4.0.1 and 9.3.0.2, including 8.3.x allow certain web services to set property values which contain Spring templates that are interpreted downstream.

Affected products

  • Hitachi Vantara Pentaho Business Analytics Server: from 8.3.0.0, before 9.3.0.2 (fixed in 9.3.0.2); version 9.4.0.0 only

Published 2023-04-03. Last modified 2026-06-17.