Hitachi Vantara Pentaho Business Analytics Server prior to versions 9.4.0.0 and 9.3.0.2, including 8.3.x display the full parametrized SQL query in an error message when an invalid character is used within a Pentaho Report (*.prpt).
Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2022-52067 | Hitachi Vantara Pentaho Business Analytics Server prior to versions 9.4.0.0 and 9.3.0.2, including 8.3.x display the full parametrized SQL query in an error message when an invalid character is used within a Pentaho Report (*.prpt). |
Tue, 11 Feb 2025 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Status: PUBLISHED
Assigner: HITVAN
Published:
Updated: 2025-02-11T14:28:35.632Z
Reserved: 2022-12-27T22:39:50.860Z
Link: CVE-2022-4770
Updated: 2024-08-03T01:48:40.442Z
Status : Modified
Published: 2023-04-03T19:15:07.227
Modified: 2024-11-21T07:35:54.500
Link: CVE-2022-4770
No data.
OpenCVE Enrichment
No data.
EUVD