Hitachi Vantara Pentaho Data Integration & Analytics of all versions contain a JDBC driver for H2 databases which is vulnerable to external script execution when a new connection is created by a data source administrator.
When creating a new connection to an H2 database by a data source administrator, the built-in JDBC driver processes connection parameters in a way that allows execution of external scripts. An attacker with data source administrator privileges can construct a malicious JDBC connection string that will trigger execution of arbitrary code or script on the server side. The vulnerability has a scope extending beyond the component (Scope: Changed), which means that the impact may affect resources outside the direct application environment.
An attacker with data source administrator privileges can cause complete compromise of confidentiality, integrity and availability of the system, including remote code execution (RCE) on the server hosting the application.
Software should be updated to version 10.2.0.7 or 11.0.0.0 according to the manufacturer's information available at the address indicated in the references. Additionally, it is recommended to restrict access to data source management functions exclusively to trusted and verified administrators.
Hitachi Vantara Pentaho Data Integration & Analytics – all versions before 10.2.0.7 and before 11.0.0.0
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:HHitachi Vantara Pentaho Data Integration And Analytics
APPHitachi< 10.2.0.7
Related vulnerabilities
RCE przez brak restrykcji skryptów Groovy w raportach PRPT — Pentaho
Hitachi Vantara Pentaho Data Integration & Analytics versions before 10.2.0.7 and 11.0.0.0, including 9.3.x an...
Hitachi Vantara Pentaho Data Integration & Analytics w wersjach poniżej 10.2.0.6 i 11.0.0.0, w tym 9.3.x i 8.3...
Wersje Hitachi Vantara Pentaho Data Integration & Analytics poprzedzające 10.2.0.6 i 11.0.0.0, w tym 10.2.0.6 ...
Hitachi Vantara Pentaho Data Integration & Analytics versions before 10.1.0.0 and 9.3.0.6, including 9.5.x an...