Hitachi Vantara Pentaho Business Analytics Server versions before 9.4.0.1 and 9.3.0.3, including 8.3.x deserialize untrusted JSON data without constraining the parser to approved classes and methods.
References
Configurations
Configuration 1 (hide)
|
History
No history.
Information
Published : 2023-05-24 22:15
Updated : 2023-06-01 15:45
NVD link : CVE-2022-4815
Mitre link : CVE-2022-4815
CVE.ORG link : CVE-2022-4815
JSON object : View
Products Affected
hitachi
- vantara_pentaho
- vantara_pentaho_business_analytics_server
CWE
CWE-502
Deserialization of Untrusted Data