CVE-2023-3517

EUVD-2023-44175
Hitachi Vantara Pentaho Data Integration & Analytics versions before 9.5.0.1 and 9.3.0.5, including 
8.3.x does not restrict JNDI identifiers during the creation of XActions, allowing control of system level data sources.

Resource Injection
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
8.5 HIGH
NETWORK
LOW
LOW
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:H/A:N
HITVANCNA
8.5 HIGH
NETWORK
LOW
LOW
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:H/A:N
Base Score
CVSS 3.x
EPSS Score
Percentile: 31%
Affected Products (NVD)
VendorProductVersion
hitachipentaho_data_integration_and_analytics
1.0 ≤
𝑥
< 9.3.0.5
hitachipentaho_data_integration_and_analytics
9.4.0.0 ≤
𝑥
< 9.5.0.1
𝑥
= Vulnerable software versions