Vulnerability Description
Hitachi Vantara Pentaho Data Integration & Analytics versions before 9.5.0.1 and 9.3.0.5, including 8.3.x does not restrict JNDI identifiers during the creation of XActions, allowing control of system level data sources.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Hitachi | Pentaho Data Integration And Analytics | >= 1.0, < 9.3.0.5 |
Related Weaknesses (CWE)
References
- https://support.pentaho.com/hc/en-us/articles/19668665099533Vendor Advisory
- https://support.pentaho.com/hc/en-us/articles/19668665099533Vendor Advisory
FAQ
What is CVE-2023-3517?
CVE-2023-3517 is a vulnerability with a CVSS score of 8.5 (HIGH). Hitachi Vantara Pentaho Data Integration & Analytics versions before 9.5.0.1 and 9.3.0.5, including 8.3.x does not restrict JNDI identifiers during the creation of XActions, allowing control of syst...
How severe is CVE-2023-3517?
CVE-2023-3517 has been rated HIGH with a CVSS base score of 8.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2023-3517?
Check the references section above for vendor advisories and patch information. Affected products include: Hitachi Pentaho Data Integration And Analytics.