vulns.coMCP

← CVE intelligence

CVE-2022-43939 - Hitachi Vantara Pentaho BA Server Authorization Bypass Vulnerability

Hitachi Vantara Pentaho BA Server contains a use of non-canonical URL paths for authorization decisions vulnerability that enables an attacker to bypass authorization.

Severity
critical
Product
Hitachi Vantara Pentaho Business Analytics (BA) Server
Published
2025-03-03
EPSS
0.923
CISA KEV
Known exploited
Ransomware
Known campaign use

References and validation

Entries are refreshed from CISA KEV and FIRST EPSS. Validate applicability before testing.