← Vulnerability feed

Vulnerability record · CVE-2022-43939 · published 3 April 2023

CVE-2022-43939: Pentaho Business Analytics Server authorization bypass via non-canonical URLs

Hitachi · Vantara Pentaho Business Analytics Server

Hitachi Vantara Pentaho Business Analytics Server versions before 9.4.0.1 and 9.3.0.2, including 8.3.x, makes authorization decisions using non-canonical URL paths that can be circumvented. Because the check can be bypassed, unauthenticated attackers can reach functionality that should be restricted. The flaw is rated critical and is listed in CISA KEV, so it warrants urgent attention.

9.8 CVSS 3.1 Critical CISA KEV since 3 Mar 2025 EPSS 92% · top 0.2% CWE-647 · CWE-647
9.8CVSS 3.1 base score
92%EPSS exploitation probability, 30 days
YesIn CISA KEV, fix deadline passed
1Affected product versions listed by NVD
5References, 2 tagged exploit
17 Jun 2026Last modified by NVD

Description

Hitachi Vantara Pentaho Business Analytics Server versions before 9.4.0.1 and 9.3.0.2, including 8.3.x contain security restrictions using non-canonical URLs which can be circumvented.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 17 September 2026. Confidence: high.

critical priorityCVSS 9.8, CISA KEV listing with a March 2025 remediation deadline, very high EPSS probability, and public exploit code make this an urgent, actively targeted flaw.

What it is

Hitachi Vantara Pentaho Business Analytics Server versions before 9.4.0.1 and 9.3.0.2, including 8.3.x, makes authorization decisions using non-canonical URL paths that can be circumvented. Because the check can be bypassed, unauthenticated attackers can reach functionality that should be restricted. The flaw is rated critical and is listed in CISA KEV, so it warrants urgent attention.

Impact

An attacker gains access to protected server functionality without authentication, and public exploit material pairs the bypass with server-side template injection leading to code execution. That can result in full compromise of the Pentaho server and its data.

Attack surface

Reachable over the network via HTTP requests to the Pentaho BA Server web interface, with no authentication and no user interaction required per the CVSS vector. The bypass relies on crafting non-canonical URL paths that evade the authorization check.

Exploitation

CVE-2022-43939 is listed in CISA KEV with a due date of 2025-03-24, and EPSS gives a 30-day probability of 0.92266 (99.8th percentile). Public exploit code is referenced on Packet Storm, and CISA records no known ransomware campaign use.

What to do

  • Upgrade Pentaho Business Analytics Server to 9.4.0.1 or 9.3.0.2 (or later) as directed by the vendor advisory.
  • If immediate patching is not possible, restrict network access to the Pentaho BA Server to trusted users and networks, or discontinue use per CISA BOD 22-01 guidance.
  • Review and normalize URL handling so authorization decisions are made on canonical paths, and test for path-based bypasses after changes.
  • Monitor vendor and CISA guidance for updated mitigations and apply them promptly given active exploitation.
  • Audit accounts and server configuration for signs of unauthorized access or template injection abuse.

Detection

  • Inspect web logs for requests using non-canonical or obfuscated URL paths (for example encoded slashes, dot segments, or duplicate separators) targeting Pentaho endpoints.
  • Alert on unauthenticated access to administrative or restricted Pentaho BA Server endpoints that normally require a session.
  • Hunt for server-side template injection indicators, such as unusual template expressions or unexpected child processes spawned by the Pentaho service.
  • Correlate Pentaho server activity with outbound connections or file writes that suggest post-exploitation code execution.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Exploitation in the wild

CISA added CVE-2022-43939 to the Known Exploited Vulnerabilities catalog on 3 March 2025 as "Hitachi Vantara Pentaho BA Server Authorization Bypass Vulnerability". Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable. Federal deadline 24 March 2025.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2022-43939 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

7.2CVE-2022-43769Hitachi Vantara Pentaho BA Server Spring Template InjectionHitachi Vantara Pentaho Business Analytics Server before 9.4.0.1 and 9.3.0.2, including 8.3.x, allows certain web services to set property values con…KEVEPSS 98%analysed8.8CVE-2022-4815Hitachi vantara pentaho deserialization of untrusted data vulnerabilityHitachi Vantara Pentaho Business Analytics Server versions before 9.4.0.1 and 9.3.0.3, including 8.3.x deserialize untrusted JSON data without constr…EPSS 0.63%8.8CVE-2022-43938Hitachi vantara pentaho business analytics server code injection vulnerabilityHitachi Vantara Pentaho Business Analytics Server prior to versions 9.4.0.1 and 9.3.0.2, including 8.3.x cannot allow a system administrator to disab…EPSS 26%8.8CVE-2022-43940Hitachi vantara pentaho business analytics server incorrect authorization vulnerabilityHitachi Vantara Pentaho Business Analytics Server versions before 9.4.0.1 and 9.3.0.2, including 8.3.x do not correctly perform an authorization chec…EPSS 0.56%8.8CVE-2022-43773Hitachi vantara pentaho business analytics server incorrect permission assignment vulnerabilityHitachi Vantara Pentaho Business Analytics Server prior to versions 9.4.0.1 and 9.3.0.2, including 8.3.x is installed with a sample HSQLDB data sourc…EPSS 22%6.5CVE-2022-43941Hitachi vantara pentaho business analytics server xml external entity (xxe) vulnerabilityHitachi Vantara Pentaho Business Analytics Server versions before 9.4.0.1 and 9.3.0.2, including 8.3.x do not correctly protect the Post Analysis ser…EPSS 0.53%6.5CVE-2022-43771Hitachi vantara pentaho business analytics server path traversal vulnerabilityHitachi Vantara Pentaho Business Analytics Server versions before 9.4.0.0 and 9.3.0.1, including 8.3.x, using the Pentaho Data Access plugin exposes …EPSS 24%6.5CVE-2022-43772Hitachi vantara pentaho business analytics server sensitive information in log file vulnerabilityHitachi Vantara Pentaho Business Analytics Server versions before 9.4.0.0 and 9.3.0.1, including 8.3.x with the Big Data Plugin expose the username a…EPSS 0.39%

Source: NIST National Vulnerability Database (record CVE-2022-43939), CISA KEV, FIRST EPSS (scores of 2026-09-24). This page is refreshed as NVD updates the record.