Vulnerabilities (CVE)

Filtered by vendor Hitachi Subscribe
Filtered by product Vantara Pentaho Data Integration And Analytics
Total 2 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2025-11158 1 Hitachi 1 Vantara Pentaho Data Integration And Analytics 2026-05-06 N/A 9.1 CRITICAL
Hitachi Vantara Pentaho Data Integration & Analytics versions before 10.2.0.6, including 9.3.x and 8.3.x, do not restrict Groovy scripts in new PRPT reports published by users, allowing insertion of arbitrary scripts and leading to a RCE.
CVE-2023-5617 1 Hitachi 1 Vantara Pentaho Data Integration And Analytics 2025-02-14 N/A 5.3 MEDIUM
Hitachi Vantara Pentaho Data Integration & Analytics versions before 10.1.0.0 and 9.3.0.6, including 9.5.x and 8.3.x, display the version of Tomcat when a server error is encountered.