EXPOSURES › CVE-2022-43939
CVE-2022-43939
HIGH ⌖ ON CISA KEV · EXPLOITEDHitachi Pentaho Business Analytics Server allowed attackers to bypass authorization controls via URL manipulation, actively exploited in the wild.
A vulnerability in Hitachi Pentaho Business Analytics Server allowed attackers to bypass authorization checks by manipulating URLs, enabling unauthorized access. DIB organizations using this product face potential data breaches and compliance failures (CMMC/NIST 800-171) and should immediately patch or mitigate the vulnerability. This highlights the importance of rigorous input validation and secure coding practices.
Shame score — The authorization bypass vulnerability, actively exploited and stemming from a fundamental flaw in authorization logic, demonstrates a significant negligence in secure development.
▸ RECOMMENDED ACTION Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Hitachi Vantara Pentaho BA Server contains a use of non-canonical URL paths for authorization decisions vulnerability that enables an attacker to bypass authorization.