LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

CVE-2022-43769: Hitachi Vantara Pentaho BA Server Special Element Injection Vulnerability

RBRecent Breaches Vulnerability Intelligence·Mar 3, 2025
High⚠ Actively exploited (CISA KEV)
High
Severity
Active
CISA KEV
No
Ransomware use
Mar 24, 2025
Patch deadline
⚠ Exploited in the wild. CISA added CVE-2022-43769 to its Known Exploited Vulnerabilities catalog on Mar 3, 2025, with a federal patch deadline of Mar 24, 2025 — meaning attackers are actively using it. If you run the affected software, patch it immediately.

Hitachi Vantara Pentaho BA Server contains a special element injection vulnerability that allows an attacker to inject Spring templates into properties files, allowing for arbitrary command execution.

CVE-2022-43769 is a special element injection vulnerability in Hitachi Vantara Pentaho Business Analytics (BA) Server. It allows an attacker to inject Spring templates into properties files, which can lead to arbitrary command execution on the affected system. This matters because Pentaho BA Server is commonly used for business intelligence and analytics workloads that often hold sensitive organizational data; successful exploitation can give an attacker a foothold for further compromise.

Public detail is limited to the CISA description of the flaw class (CWE-74). Exact affected versions, attack prerequisites, and scoring must be confirmed against the vendor advisory. Known ransomware use is not documented.

How it works

The vulnerability is classified as CWE-74, improper neutralization of special elements in output used by a downstream component (injection). In this case, an attacker can inject Spring templates into properties files processed by the Pentaho BA Server. Spring template injection can result in the server interpreting and executing attacker-controlled content as code, ultimately allowing arbitrary command execution under the privileges of the application process.

No public exploit mechanics, payloads, or preconditions beyond the CISA summary are provided here. Defenders should treat any unauthenticated or low-privilege ability to write or influence properties files as a high-risk path and verify the precise attack surface in the vendor advisory.

Am I affected? How to find it in your systems

Hitachi Vantara Pentaho Business Analytics Server typically runs as a Java-based application server in enterprise environments, often on Linux or Windows hosts, virtual machines, or containers supporting BI dashboards, reporting, and data integration. It may be exposed internally or, less commonly, to the internet.

How to remediate

Apply the vendor-supplied update or mitigation for Hitachi Vantara Pentaho BA Server as directed in the official advisory for CVE-2022-43769. This is the primary remediation. Follow any additional instructions in the advisory and, for cloud-hosted instances, applicable BOD 22-01 guidance. If mitigations are unavailable, discontinue use of the product.

If you can't patch immediately

Until the vendor update can be applied, reduce exposure with compensating controls tailored to injection flaws that enable command execution.

If your data may have been exposed

Actively exploited vulnerabilities of this class can lead to full system compromise and data breaches. If you suspect exploitation, isolate the host, preserve forensic evidence, and follow your incident-response plan. Review access logs and data stores for unauthorized activity. You can run a free exposure scan of your email addresses against known breach data to check whether credentials or personal information associated with your organization have already appeared in public dumps.

AICompiled with AI assistance from public sources and published under our editorial standards.

Details

AffectedHitachi Vantara · Pentaho Business Analytics (BA) Server
WeaknessCWE-74
Added to CISA KEVMar 3, 2025
Federal patch deadlineMar 24, 2025
Known ransomware useNot documented
Check if your data is exposed →

Official records: NVD · CISA KEV

← All actively-exploited vulnerabilities