Shodan
Maps
Images
Monitor
Developer
More...
Dashboard
View Api Docs
Vulnerabilities
By Date
Known Exploited
Advanced Search
Vulnerable Software
Vendors
Products
Vulnerability Details CVE-2022-4771
Hitachi Vantara Pentaho Business Analytics Server prior to versions 9.4.0.1 and 9.3.0.2, including 8.3.x allow a malicious URL to inject content into the Pentaho User Console through session variables.
Exploit prediction scoring system (EPSS) score
EPSS Score
0.003
EPSS Ranking
48.4%
CVSS Severity
CVSS v3 Score
5.4
References
https://support.pentaho.com/hc/en-us/articles/14455436088717--Resolved-Pentaho-BA-Server-Improper-Neutralization-of-Input-During-Web-Page-Generation-Cross-site-Scripting-Versions-before-9-4-0-1-and-9-3-0-2-including-8-3-x-Impacted-CVE-2022-4771-
https://support.pentaho.com/hc/en-us/articles/14455436088717--Resolved-Pentaho-BA-Server-Improper-Neutralization-of-Input-During-Web-Page-Generation-Cross-site-Scripting-Versions-before-9-4-0-1-and-9-3-0-2-including-8-3-x-Impacted-CVE-2022-4771-
Products affected by CVE-2022-4771
Hitachi
»
Vantara Pentaho Business Analytics Server
»
Version:
Any
cpe:2.3:a:hitachi:vantara_pentaho_business_analytics_server:*
Hitachi
»
Vantara Pentaho Business Analytics Server
»
Version:
9.4.0.0
cpe:2.3:a:hitachi:vantara_pentaho_business_analytics_server:9.4.0.0
Products
Monitor
Search Engine
Developer API
Maps
Bulk Data
Images
Snippets
Pricing
Membership
API Subscriptions
Enterprise
Contact Us
support@shodan.io
Shodan ® - All rights reserved