S4E just found a high-severity finding from top 10 tcp port service scan
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
high·Product Based Web Vulnerabilities·Updated Oct 8, 2025

CVE-2022-43939 Scanner

CVE-2022-43939 Scanner - Unauthorized Admin Access vulnerability in Hitachi Vantara Pentaho Business Analytics Server

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsurl
CostFree
3.4k
Times Used
continuous scan runs
4.7k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
🔴
CISA Known Exploited Vulnerability
This CVE is actively exploited in the wild. CISA mandates federal agencies to patch immediately.
CVECVE-2022-43939
9.8
CVSShigh
Exploitable remotely over the internet · no authentication required.

Hitachi Vantara Pentaho Business Analytics Server versions before 9.4.0.1 and 9.3.0.2, including 8.3.x contain security restrictions using non-canonical URLs which can be circumvented.

Attack Vector
Network
Privileges Req.
None
User Interaction
None
Affected
Pentaho Business Analytics Serverby Hitachi Vantara
AFFECTED< 9.3.0.2SAFE ✓≥ 9.3.0.2
Updated Aug 22, 2026View on NVD →
Detail

Hitachi Vantara Pentaho Business Analytics Server is a data analysis tool widely used in enterprise environments. It is designed to help organizations analyze data for better decision-making by providing capabilities ranging from reporting to predictive analysis. The software is used by analysts, data scientists, and business managers to gain insights from data and improve operations. By offering a seamless way to manage and interpret data, the software is a popular choice across various industries. The analytics server integrates with other business systems to provide real-time data analysis. It serves large enterprises with high data volume by supporting diverse data sources and customizable reports.

The vulnerability detected in Hitachi Vantara Pentaho Business Analytics Server allows attackers unauthorized admin access. This issue arises due to the use of non-canonical URLs that can bypass security restrictions. Since credentials are not required, this opens the system to exploitation by unauthorized entities. Critical operations that should be secure become vulnerable, posing a risk to sensitive data. The vulnerability affects specific server versions before 9.4.0.1 and 9.3.0.2, including 8.3.x. Users need to be aware of this flaw to mitigate potential risks.

Technically, the vulnerability involves the manipulation of URLs which does not adhere to canonical forms, allowing bypass of usual authorization checks. Attackers can leverage this by sending crafted HTTP requests to endpoints like '/pentaho/Login' and '/pentaho/api/ldap/config/ldapTreeNodeChildren/require.js'. Successful exploitation provides a 200 OK response, indicating unauthorized access to restricted sections. The use of certain URL paths seems to omit standard authorization procedures. Consequently, they reveal sensitive functionalities without user verification. A positive detection implies a significant lapse in authorization schemas.

Exploit of this vulnerability leads to potential unauthorized data access, configuration changes, and administrative operations. Such exploitation can result in data theft, system manipulation, and significant operational disruptions. The business analytics server, a critical component in organizational IT infrastructure, when compromised, can lead to severe confidentiality, integrity, and availability risks. This could undermine trust in data accuracy and reliability, impacting business decisions. Users should address this vulnerability promptly to prevent adverse outcomes.

REFERENCES

Solution Advice
  • Upgrade to secure system versions: Ensure installation or upgrade to version 9.4.0.1 and above or 9.3.0.2 and above to close this vulnerability.
  • Implement URL validation: Employ proper canonicalization of URLs to prevent bypassing of authorization mechanisms.
  • Use comprehensive access controls: Strengthen authorization schemes to detect and block malformed HTTP requests.
  • Apply security patches: Regularly apply security updates provided by Hitachi to safeguard against known vulnerabilities.
  • Conduct security audits: Regular security assessments to monitor and enhance authorization systems to prevent unauthorized access.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.