CVE-2025-11159
Hitachi Vantara Pentaho Data Integration & Analytics of all versions contain a JDBC driver for H2 databases which is vulnerable to external script execution when a new connection is created by a data source administrator.
Scoring
- Severity
- CRITICAL
- CVSS base score
- 9.1
- CVSS vector
- CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
- EPSS probability
- 0.34%
- CWE
- CWE-1395
- Published
- 2026-05-13
- Last modified
- 2026-05-13
Affected products
- Hitachi Vantara Pentaho Data Integration and Analytics
Weakness type
Related vulnerabilities
- CVE-2026-69713 — Windows Secure Boot Security Feature Bypass Vulnerability
- CVE-2026-58235 — Use of Vulnerable Third-Party Component in SAP NetWeaver AS Java (Adobe Document Services)
- CVE-2026-58586 — Image::WebP versions before 0.3.0 for Perl bundle a vulnerable version of libwebp
- CVE-2026-16634 — TOML::XS versions before 0.06 for Perl bundle an unsupported and vulnerable version of tomlc99
- CVE-2026-55789 — Logto: SAML IdP injects user-controlled profile attributes raw into signed assertions, allowing privilege escalation at relying Service Providers
- CVE-2026-47906 — Dreamweaver Desktop | Dependency on Vulnerable Third-Party Component (CWE-1395)
- CVE-2026-8993 — Improper URL Handler Processing in D.Launcher 2 enables NTLM Credential Disclosure and SSRF attacks
- CVE-2025-31973 — HCL BigFix Service Management (SM) is susceptible to a Configuration – 'Insecure Use of Base Image Version'