CVE-2022-43938
Hitachi Vantara Pentaho Business Analytics Server prior to versions 9.4.0.1 and 9.3.0.2, including 8.3.x cannot allow a system administrator to disable scripting capabilities of Pentaho Reports (*.prpt) through the JVM script manager.
Scoring
- Severity
- HIGH
- CVSS base score
- 8.8
- CVSS vector
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
- EPSS probability
- 22.60%
- CWE
- CWE-96
- Published
- 2023-04-03
- Last modified
- 2026-03-13
Affected products
- Hitachi Vantara Pentaho Business Analytics Server
- Hitachi Vantara Pentaho Business Analytics Server
Weakness type
Related vulnerabilities
- CVE-2024-55877 — XWiki allows remote code execution from account through macro descriptions and XWiki.XWikiSyntaxMacrosList
- CVE-2026-86218 — pre-authentication remote code execution
- CVE-2020-6144 — A remote code execution vulnerability exists in the install functionality of OS4Ed openSIS 7.4. The username variable wh
- CVE-2020-6143 — A remote code execution vulnerability exists in the install functionality of OS4Ed openSIS 7.4. The password variable wh
- CVE-2024-55662 — XWiki allows remote code execution through the extension sheet
- CVE-2015-2079 — Usermin 0.980 through 1.x before 1.660 allows uconfig_save.cgi sig_file_free remote code execution because it uses the t
- CVE-2025-30091 — In Tiny MoxieManager PHP before 4.0.0, remote code execution can occur in the installer command. This vulnerability allo
- CVE-2024-43400 — XWiki Platform allows XSS through XClass name in string properties