CRITICAL🇵🇱 Wersja polska

CVE-2025-11159

CVSS 9.1v3.1pub. 2026-05-13upd. 2026-06-02

Hitachi Vantara Pentaho Data Integration & Analytics of all versions contain a JDBC driver for H2 databases which is vulnerable to external script execution when a new connection is created by a data source administrator.

🤖 AI Analysis
How it works

When creating a new connection to an H2 database by a data source administrator, the built-in JDBC driver processes connection parameters in a way that allows execution of external scripts. An attacker with data source administrator privileges can construct a malicious JDBC connection string that will trigger execution of arbitrary code or script on the server side. The vulnerability has a scope extending beyond the component (Scope: Changed), which means that the impact may affect resources outside the direct application environment.

Impact

An attacker with data source administrator privileges can cause complete compromise of confidentiality, integrity and availability of the system, including remote code execution (RCE) on the server hosting the application.

Mitigation & patch

Software should be updated to version 10.2.0.7 or 11.0.0.0 according to the manufacturer's information available at the address indicated in the references. Additionally, it is recommended to restrict access to data source management functions exclusively to trusted and verified administrators.

Who is affected

Hitachi Vantara Pentaho Data Integration & Analytics – all versions before 10.2.0.7 and before 11.0.0.0

Analysis generated by Claude AI (Anthropic) based on NVD data. Always verify with vendor.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
  • Hitachi Vantara Pentaho Data Integration And Analytics

    APP
    Hitachi
    < 10.2.0.7
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
CWE
References

Related vulnerabilities

CVE-2025-11158CRITICAL9.1PL ✓same product

RCE przez brak restrykcji skryptów Groovy w raportach PRPT — Pentaho

CVE-2026-2253HIGH7.7same product

Hitachi Vantara Pentaho Data Integration & Analytics versions before 10.2.0.7 and 11.0.0.0, including 9.3.x an...

CVE-2026-2254MEDIUM6.3same product

Hitachi Vantara Pentaho Data Integration & Analytics w wersjach poniżej 10.2.0.6 i 11.0.0.0, w tym 9.3.x i 8.3...

CVE-2026-2255MEDIUM4.3same product

Wersje Hitachi Vantara Pentaho Data Integration & Analytics poprzedzające 10.2.0.6 i 11.0.0.0, w tym 10.2.0.6 ...

CVE-2023-5617MEDIUM5.3same product

Hitachi Vantara Pentaho Data Integration & Analytics versions before 10.1.0.0 and 9.3.0.6, including 9.5.x an...