CVE-2023-3517

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
12/12/2023
Last modified:
18/12/2023

Description

<br /> Hitachi Vantara Pentaho Data Integration &amp; Analytics versions before 9.5.0.1 and 9.3.0.5, including <br /> 8.3.x does not restrict JNDI identifiers during the creation of XActions, allowing control of system level data sources.<br /> <br />

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:hitachi:pentaho_data_integration_and_analytics:*:*:*:*:*:*:*:* 1.0 (including) 9.3.0.5 (excluding)
cpe:2.3:a:hitachi:pentaho_data_integration_and_analytics:*:*:*:*:*:*:*:* 9.4.0.0 (including) 9.5.0.1 (excluding)


References to Advisories, Solutions, and Tools