LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

CVE-2022-43939: Hitachi Vantara Pentaho BA Server Authorization Bypass Vulnerability

RBRecent Breaches Vulnerability Intelligence·Mar 3, 2025
High⚠ Actively exploited (CISA KEV)
High
Severity
Active
CISA KEV
No
Ransomware use
Mar 24, 2025
Patch deadline
⚠ Exploited in the wild. CISA added CVE-2022-43939 to its Known Exploited Vulnerabilities catalog on Mar 3, 2025, with a federal patch deadline of Mar 24, 2025 — meaning attackers are actively using it. If you run the affected software, patch it immediately.

Hitachi Vantara Pentaho BA Server contains a use of non-canonical URL paths for authorization decisions vulnerability that enables an attacker to bypass authorization.

CVE-2022-43939 is an authorization bypass vulnerability in Hitachi Vantara Pentaho Business Analytics (BA) Server. It stems from the use of non-canonical URL paths when making authorization decisions, allowing an attacker to bypass intended access controls. This matters because BA Server typically holds business intelligence data, reports, and analytics that may include sensitive organizational information; successful abuse can grant unauthorized access without needing legitimate credentials for protected resources.

Defenders should treat this as a high-priority authorization flaw in any deployment of the product. Confirm all version-specific impact, fixed releases, and exact remediation steps against the vendor advisory, as public details beyond the CWE and CISA summary are limited here.

How it works

The weakness is classified as CWE-647: Use of Non-Canonical URL Paths for Authorization Decisions. In this class of flaw, the application evaluates access rights based on a URL path that has not been normalized to a single canonical form. An attacker can supply a non-canonical representation of a protected path—such as one that includes alternate encodings, path traversal sequences, or other equivalent forms that the authorization logic does not fully resolve—while the underlying resource handler still processes the request as if it were authorized.

According to the CISA summary, Hitachi Vantara Pentaho BA Server contains this vulnerability, enabling an attacker to bypass authorization. No further exploit mechanics, payloads, or prerequisites are provided in the available facts; treat any concrete attack chain as something that must be validated against the vendor advisory and your own testing. The practical result is that an unauthenticated or low-privilege user may reach functionality or data that the product’s access-control rules were intended to restrict.

Am I affected? How to find it in your systems

Pentaho BA Server is typically deployed as an on-premises or private-cloud analytics platform used for reporting, dashboards, and data integration. It often runs as a Java-based web application on application servers, listening on HTTP/HTTPS ports and integrated with corporate identity stores or databases.

If the product is exposed to untrusted networks or the internet, prioritize those instances. Cloud-hosted deployments should also follow any applicable BOD 22-01 guidance referenced by CISA.

How to remediate

Apply the vendor-supplied update or mitigation for CVE-2022-43939 as the primary remediation. CISA’s required action is to apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable. Obtain the patch or configuration change directly from Hitachi Vantara and validate it in a non-production environment before broad rollout.

If you can't patch immediately

Until the vendor update can be applied, reduce exposure with compensating controls focused on this authorization-bypass class.

If your data may have been exposed

Actively exploited authorization-bypass vulnerabilities can lead to unauthorized data access and subsequent breaches. Known ransomware use of this specific CVE is not documented in the available facts. If you suspect compromise, isolate affected systems, preserve logs, and initiate your incident-response process. As a quick personal check, you can run a free exposure scan of your email address against known breach data sets to see whether associated credentials or personal information have already appeared in public breach collections.

AICompiled with AI assistance from public sources and published under our editorial standards.

Details

AffectedHitachi Vantara · Pentaho Business Analytics (BA) Server
WeaknessCWE-647
Added to CISA KEVMar 3, 2025
Federal patch deadlineMar 24, 2025
Known ransomware useNot documented
Check if your data is exposed →

Official records: NVD · CISA KEV

← All actively-exploited vulnerabilities