CVE Vulnerabilities

CVE-2023-3517

Published: Dec 12, 2023 | Modified: Dec 18, 2023
CVSS 3.x
8.8
HIGH
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu

Hitachi Vantara Pentaho Data Integration & Analytics versions before 9.5.0.1 and 9.3.0.5, including 8.3.x does not restrict JNDI identifiers during the creation of XActions, allowing control of system level data sources.

Affected Software

Name Vendor Start Version End Version
Pentaho_data_integration_and_analytics Hitachi 1.0 (including) 9.3.0.5 (excluding)
Pentaho_data_integration_and_analytics Hitachi 9.4.0.0 (including) 9.5.0.1 (excluding)

References