CVE-2023-3517
12.12.2023, 23:15
Hitachi Vantara Pentaho Data Integration & Analytics versions before 9.5.0.1 and 9.3.0.5, including 8.3.x does not restrict JNDI identifiers during the creation of XActions, allowing control of system level data sources.
Vendor | Product | Version |
---|---|---|
hitachi | pentaho_data_integration_and_analytics | 1.0 ≤ 𝑥 < 9.3.0.5 |
hitachi | pentaho_data_integration_and_analytics | 9.4.0.0 ≤ 𝑥 < 9.5.0.1 |
𝑥
= Vulnerable software versions