CRITICAL🇵🇱 Wersja polska

CVE-2025-11158

CVSS 9.1v3.1pub. 2026-03-10upd. 2026-05-06

Hitachi Vantara Pentaho Data Integration & Analytics versions before 10.2.0.6, including 9.3.x and 8.3.x, do not restrict Groovy scripts in new PRPT reports published by users, allowing insertion of arbitrary scripts and leading to a RCE.

🤖 AI Analysis
How it works

A user with access to the system can publish a new PRPT report containing an embedded, malicious Groovy script. The platform does not verify or restrict the contents of such scripts before execution (CWE-862: missing authorization). When the report is processed, the script is executed in the server context, allowing the attacker to execute arbitrary system commands.

Impact

The attacker can gain full control over the server, including reading and modifying sensitive data, installing malicious software, or leveraging the compromised system for further attacks on the infrastructure (lateral movement). The scope of the vulnerability covers full confidentiality, integrity, and availability of the system.

Mitigation & patch

The software must be updated to version 10.2.0.6 or later. Details regarding the patch are available in the official security notice from the vendor at the address indicated in the references.

Who is affected

Hitachi Vantara Pentaho Data Integration & Analytics in versions before 10.2.0.6, including branches 9.3.x and 8.3.x

Analysis generated by Claude AI (Anthropic) based on NVD data. Always verify with vendor.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
  • Hitachi Vantara Pentaho Data Integration And Analytics

    APP
    Hitachi
    < 10.2.0.6
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
CWE
References

Related vulnerabilities

CVE-2025-11159CRITICAL9.1PL ✓same product

Hitachi Vantara Pentaho – RCE przez podatny sterownik JDBC H2

CVE-2026-2253HIGH7.7same product

Hitachi Vantara Pentaho Data Integration & Analytics versions before 10.2.0.7 and 11.0.0.0, including 9.3.x an...

CVE-2026-2254MEDIUM6.3same product

Hitachi Vantara Pentaho Data Integration & Analytics w wersjach poniżej 10.2.0.6 i 11.0.0.0, w tym 9.3.x i 8.3...

CVE-2026-2255MEDIUM4.3same product

Wersje Hitachi Vantara Pentaho Data Integration & Analytics poprzedzające 10.2.0.6 i 11.0.0.0, w tym 10.2.0.6 ...

CVE-2023-5617MEDIUM5.3same product

Hitachi Vantara Pentaho Data Integration & Analytics versions before 10.1.0.0 and 9.3.0.6, including 9.5.x an...