Hitachi Vantara Pentaho Data Integration & Analytics versions before 10.2.0.6, including 9.3.x and 8.3.x, do not restrict Groovy scripts in new PRPT reports published by users, allowing insertion of arbitrary scripts and leading to a RCE.
A user with access to the system can publish a new PRPT report containing an embedded, malicious Groovy script. The platform does not verify or restrict the contents of such scripts before execution (CWE-862: missing authorization). When the report is processed, the script is executed in the server context, allowing the attacker to execute arbitrary system commands.
The attacker can gain full control over the server, including reading and modifying sensitive data, installing malicious software, or leveraging the compromised system for further attacks on the infrastructure (lateral movement). The scope of the vulnerability covers full confidentiality, integrity, and availability of the system.
The software must be updated to version 10.2.0.6 or later. Details regarding the patch are available in the official security notice from the vendor at the address indicated in the references.
Hitachi Vantara Pentaho Data Integration & Analytics in versions before 10.2.0.6, including branches 9.3.x and 8.3.x
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:HHitachi Vantara Pentaho Data Integration And Analytics
APPHitachi< 10.2.0.6
Related vulnerabilities
Hitachi Vantara Pentaho – RCE przez podatny sterownik JDBC H2
Hitachi Vantara Pentaho Data Integration & Analytics versions before 10.2.0.7 and 11.0.0.0, including 9.3.x an...
Hitachi Vantara Pentaho Data Integration & Analytics w wersjach poniżej 10.2.0.6 i 11.0.0.0, w tym 9.3.x i 8.3...
Wersje Hitachi Vantara Pentaho Data Integration & Analytics poprzedzające 10.2.0.6 i 11.0.0.0, w tym 10.2.0.6 ...
Hitachi Vantara Pentaho Data Integration & Analytics versions before 10.1.0.0 and 9.3.0.6, including 9.5.x an...