Vulnerability record · CVE-2022-43939 · published 3 April 2023
CVE-2022-43939: Pentaho Business Analytics Server authorization bypass via non-canonical URLs
Hitachi · Vantara Pentaho Business Analytics Server
Hitachi Vantara Pentaho Business Analytics Server versions before 9.4.0.1 and 9.3.0.2, including 8.3.x, makes authorization decisions using non-canonical URL paths that can be circumvented. Because the check can be bypassed, unauthenticated attackers can reach functionality that should be restricted. The flaw is rated critical and is listed in CISA KEV, so it warrants urgent attention.
Description
Hitachi Vantara Pentaho Business Analytics Server versions before 9.4.0.1 and 9.3.0.2, including 8.3.x contain security restrictions using non-canonical URLs which can be circumvented.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Automated analysis
critical priorityCVSS 9.8, CISA KEV listing with a March 2025 remediation deadline, very high EPSS probability, and public exploit code make this an urgent, actively targeted flaw.
What it is
Hitachi Vantara Pentaho Business Analytics Server versions before 9.4.0.1 and 9.3.0.2, including 8.3.x, makes authorization decisions using non-canonical URL paths that can be circumvented. Because the check can be bypassed, unauthenticated attackers can reach functionality that should be restricted. The flaw is rated critical and is listed in CISA KEV, so it warrants urgent attention.
Impact
An attacker gains access to protected server functionality without authentication, and public exploit material pairs the bypass with server-side template injection leading to code execution. That can result in full compromise of the Pentaho server and its data.
Attack surface
Reachable over the network via HTTP requests to the Pentaho BA Server web interface, with no authentication and no user interaction required per the CVSS vector. The bypass relies on crafting non-canonical URL paths that evade the authorization check.
Exploitation
CVE-2022-43939 is listed in CISA KEV with a due date of 2025-03-24, and EPSS gives a 30-day probability of 0.92266 (99.8th percentile). Public exploit code is referenced on Packet Storm, and CISA records no known ransomware campaign use.
What to do
- Upgrade Pentaho Business Analytics Server to 9.4.0.1 or 9.3.0.2 (or later) as directed by the vendor advisory.
- If immediate patching is not possible, restrict network access to the Pentaho BA Server to trusted users and networks, or discontinue use per CISA BOD 22-01 guidance.
- Review and normalize URL handling so authorization decisions are made on canonical paths, and test for path-based bypasses after changes.
- Monitor vendor and CISA guidance for updated mitigations and apply them promptly given active exploitation.
- Audit accounts and server configuration for signs of unauthorized access or template injection abuse.
Detection
- Inspect web logs for requests using non-canonical or obfuscated URL paths (for example encoded slashes, dot segments, or duplicate separators) targeting Pentaho endpoints.
- Alert on unauthenticated access to administrative or restricted Pentaho BA Server endpoints that normally require a session.
- Hunt for server-side template injection indicators, such as unusual template expressions or unexpected child processes spawned by the Pentaho service.
- Correlate Pentaho server activity with outbound connections or file writes that suggest post-exploitation code execution.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Exploitation in the wild
CISA added CVE-2022-43939 to the Known Exploited Vulnerabilities catalog on 3 March 2025 as "Hitachi Vantara Pentaho BA Server Authorization Bypass Vulnerability". Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable. Federal deadline 24 March 2025.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2022-43939 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2022-43939), CISA KEV, FIRST EPSS (scores of 2026-09-24). This page is refreshed as NVD updates the record.