ID

VAR-202305-2304


CVE

CVE-2022-4815


TITLE

Hitachi Vantara's  Vantara Pentaho  and  Pentaho Business Analytics  Untrusted Data Deserialization Vulnerability in

Trust: 0.8

sources: JVNDB: JVNDB-2022-024892

DESCRIPTION

Hitachi Vantara Pentaho Business Analytics Server versions before 9.4.0.1 and 9.3.0.3, including 8.3.x deserialize untrusted JSON data without constraining the parser to approved classes and methods. (DoS) It may be in a state

Trust: 1.71

sources: NVD: CVE-2022-4815 // JVNDB: JVNDB-2022-024892 // VULMON: CVE-2022-4815

AFFECTED PRODUCTS

vendor:hitachimodel:vantara pentaho business analytics serverscope:gteversion:9.3.0.0

Trust: 1.0

vendor:hitachimodel:vantara pentaho business analytics serverscope:eqversion:9.4.0.0

Trust: 1.0

vendor:hitachimodel:vantara pentahoscope:lteversion:8.3.0.25

Trust: 1.0

vendor:hitachimodel:vantara pentaho business analytics serverscope:lteversion:9.3.0.3

Trust: 1.0

vendor:hitachimodel:vantara pentahoscope:gteversion:8.3.0.0

Trust: 1.0

vendor:日立ヴァンタラmodel:vantara pentahoscope:eqversion:8.3.0.0 to 8.3.0.25

Trust: 0.8

vendor:日立ヴァンタラmodel:pentaho business analyticsscope: - version: -

Trust: 0.8

sources: JVNDB: JVNDB-2022-024892 // NVD: CVE-2022-4815

CVSS

SEVERITY

CVSSV2

CVSSV3

nvd@nist.gov: CVE-2022-4815
value: HIGH

Trust: 1.0

security.vulnerabilities@hitachivantara.com: CVE-2022-4815
value: HIGH

Trust: 1.0

NVD: CVE-2022-4815
value: HIGH

Trust: 0.8

CNNVD: CNNVD-202305-2168
value: HIGH

Trust: 0.6

nvd@nist.gov: CVE-2022-4815
baseSeverity: HIGH
baseScore: 8.8
vectorString: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
attackVector: NETWORK
attackComplexity: LOW
privilegesRequired: LOW
userInteraction: NONE
scope: UNCHANGED
confidentialityImpact: HIGH
integrityImpact: HIGH
availabilityImpact: HIGH
exploitabilityScore: 2.8
impactScore: 5.9
version: 3.1

Trust: 1.0

security.vulnerabilities@hitachivantara.com: CVE-2022-4815
baseSeverity: HIGH
baseScore: 8.0
vectorString: CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H
attackVector: NETWORK
attackComplexity: LOW
privilegesRequired: LOW
userInteraction: REQUIRED
scope: UNCHANGED
confidentialityImpact: HIGH
integrityImpact: HIGH
availabilityImpact: HIGH
exploitabilityScore: 2.1
impactScore: 5.9
version: 3.1

Trust: 1.0

NVD: CVE-2022-4815
baseSeverity: HIGH
baseScore: 8.8
vectorString: CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
attackVector: NETWORK
attackComplexity: LOW
privilegesRequired: LOW
userInteraction: NONE
scope: UNCHANGED
confidentialityImpact: HIGH
integrityImpact: HIGH
availabilityImpact: HIGH
exploitabilityScore: NONE
impactScore: NONE
version: 3.0

Trust: 0.8

sources: JVNDB: JVNDB-2022-024892 // CNNVD: CNNVD-202305-2168 // NVD: CVE-2022-4815 // NVD: CVE-2022-4815

PROBLEMTYPE DATA

problemtype:CWE-502

Trust: 1.0

problemtype:Deserialization of untrusted data (CWE-502) [NVD evaluation ]

Trust: 0.8

sources: JVNDB: JVNDB-2022-024892 // NVD: CVE-2022-4815

THREAT TYPE

remote

Trust: 0.6

sources: CNNVD: CNNVD-202305-2168

TYPE

code problem

Trust: 0.6

sources: CNNVD: CNNVD-202305-2168

PATCH

title:(Resolved) Pentaho BA Server - Deserialization of Untrusted Data - Versions before 9.4.0.1 and 9.3.0.3, including 8.3.x Impacted (CVE-2022-4815)url:https://support.pentaho.com/hc/en-us/articles/14455879270285-IMPORTANT-Resolved-Pentaho-BA-Server-Deserialization-of-Untrusted-Data-Versions-before-9-4-0-1-and-9-3-0-3-including-8-3-x-Impacted-CVE-2022-4815-

Trust: 0.8

title:Hitachi Vantara Pentaho Business Analytics Server Fixes for code issue vulnerabilitiesurl:http://123.124.177.30/web/xxk/bdxqById.tag?id=240065

Trust: 0.6

sources: JVNDB: JVNDB-2022-024892 // CNNVD: CNNVD-202305-2168

EXTERNAL IDS

db:NVDid:CVE-2022-4815

Trust: 3.3

db:JVNDBid:JVNDB-2022-024892

Trust: 0.8

db:CNNVDid:CNNVD-202305-2168

Trust: 0.6

db:VULMONid:CVE-2022-4815

Trust: 0.1

sources: VULMON: CVE-2022-4815 // JVNDB: JVNDB-2022-024892 // CNNVD: CNNVD-202305-2168 // NVD: CVE-2022-4815

REFERENCES

url:https://support.pentaho.com/hc/en-us/articles/14455879270285-important-resolved-pentaho-ba-server-deserialization-of-untrusted-data-versions-before-9-4-0-1-and-9-3-0-3-including-8-3-x-impacted-cve-2022-4815-

Trust: 1.7

url:https://nvd.nist.gov/vuln/detail/cve-2022-4815

Trust: 0.8

url:https://cxsecurity.com/cveshow/cve-2022-4815/

Trust: 0.6

url:https://nvd.nist.gov

Trust: 0.1

sources: VULMON: CVE-2022-4815 // JVNDB: JVNDB-2022-024892 // CNNVD: CNNVD-202305-2168 // NVD: CVE-2022-4815

SOURCES

db:VULMONid:CVE-2022-4815
db:JVNDBid:JVNDB-2022-024892
db:CNNVDid:CNNVD-202305-2168
db:NVDid:CVE-2022-4815

LAST UPDATE DATE

2024-08-14T14:54:46.051000+00:00


SOURCES UPDATE DATE

db:VULMONid:CVE-2022-4815date:2023-05-25T00:00:00
db:JVNDBid:JVNDB-2022-024892date:2024-01-24T04:40:00
db:CNNVDid:CNNVD-202305-2168date:2023-06-02T00:00:00
db:NVDid:CVE-2022-4815date:2023-06-01T15:45:06.507

SOURCES RELEASE DATE

db:VULMONid:CVE-2022-4815date:2023-05-24T00:00:00
db:JVNDBid:JVNDB-2022-024892date:2024-01-24T00:00:00
db:CNNVDid:CNNVD-202305-2168date:2023-05-24T00:00:00
db:NVDid:CVE-2022-4815date:2023-05-24T22:15:09