CVE-2023-3517

Hitachi Vantara Pentaho Data Integration & Analytics versions before 9.5.0.1 and 9.3.0.5, including 
8.3.x does not restrict JNDI identifiers during the creation of XActions, allowing control of system level data sources.

Resource Injection
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
8.5 HIGH
NETWORK
LOW
LOW
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:H/A:N
Base Score
CVSS 3.x
EPSS Score
Percentile: Unknown
Affected Products (NVD)
VendorProductVersion
hitachipentaho_data_integration_and_analytics
1.0 ≤
𝑥
< 9.3.0.5
hitachipentaho_data_integration_and_analytics
9.4.0.0 ≤
𝑥
< 9.5.0.1
𝑥
= Vulnerable software versions