Hitachi Vantara Pentaho Business Analytics Server prior to versions 9.4.0.1 and 9.3.0.2, including 8.3.x allow certain web services to set property values which contain Spring templates that are interpreted downstream.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.938
EPSS Ranking 99.8%
CVSS Severity
CVSS v3 Score 8.8
Proposed Action
Hitachi Vantara Pentaho BA Server contains a special element injection vulnerability that allows an attacker to inject Spring templates into properties files, allowing for arbitrary command execution.