EXPOSURES › CVE-2022-43769
CVE-2022-43769
HIGH ⌖ ON CISA KEV · EXPLOITEDHitachi Pentaho BA Server allowed arbitrary command execution via Spring template injection in properties files, actively exploited in the wild.
A vulnerability in Hitachi Vantara's Pentaho BA Server allowed attackers to inject Spring templates, leading to arbitrary command execution. DIB organizations using this product face significant risk of compromise and potential CMMC non-compliance; immediate patching and security review are critical. This highlights the importance of rigorous vendor risk management and vulnerability scanning.
Shame score — The vulnerability enabled arbitrary command execution and was actively exploited, indicating a significant design or configuration flaw with potential for widespread impact.
▸ RECOMMENDED ACTION Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Hitachi Vantara Pentaho BA Server contains a special element injection vulnerability that allows an attacker to inject Spring templates into properties files, allowing for arbitrary command execution.