CVE-2022-4815: Hitachi Vantara Pentaho

High severity, CVSS 8.8. EPSS: 0.6% chance of exploitation in the next 30 days.

Hitachi Vantara Pentaho Business Analytics Server versions before 9.4.0.1 and 9.3.0.3, including 8.3.x deserialize untrusted JSON data without constraining the parser to approved classes and methods. 

Affected products

  • Hitachi Vantara Pentaho: from 8.3.0.0, up to and including 8.3.0.25
  • Hitachi Vantara Pentaho Business Analytics Server: from 9.3.0.0, up to and including 9.3.0.3; version 9.4.0.0 only

Published 2023-05-24. Last modified 2026-06-17.