Hitachi Vantara Pentaho Business Analytics Server versions before 9.4.0.1 and 9.3.0.3, including 8.3.x deserialize untrusted JSON data without constraining the parser to approved classes and methods.
The product deserializes untrusted data without sufficiently ensuring that the resulting data will be valid.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Vantara_pentaho | Hitachi | 8.3.0.0 (including) | 8.3.0.25 (including) |
Vantara_pentaho_business_analytics_server | Hitachi | 9.3.0.0 (including) | 9.3.0.3 (including) |
Vantara_pentaho_business_analytics_server | Hitachi | 9.4.0.0 (including) | 9.4.0.0 (including) |