Support Expiration Notice: Pentaho 9.3 will reach end of support on July 1, 2026. See this article for details.

Get a grip on your data

With battle-tested solutions and a focus on foundational strength,

Pentaho helps you meet the challenges of an AI-driven world.

(Resolved) Hitachi Vantara Pentaho Business Analytics Server - Generation of Error Message Containing Sensitive Information - Versions before 10.2.0.4 Impacted (CVE-2025-9122)

Overview 

The software generates an error message that includes sensitive information about its environment, users, or associated data. (CWE-209) 

 

Products Affected 

Hitachi Vantara Pentaho Data Integration and Analytics Community Dashboard Framework prior to versions 10.2.0.4, including 9.3.0.x and 8.3.x

 

Description 

Hitachi Vantara Pentaho Data Integration and Analytics Community Dashboard Framework prior to versions 10.2.0.4, including 9.3.0.x and 8.3.x display the full server stack trace when encountering an error within the GetCdfResource servlet. 

 

Impact 

An attacker may use the contents of error messages to help launch another, more focused attack. An attack using SQL injection (CWE-89) might not initially succeed, but an error message could reveal the malformed query, which would expose query logic and possibly even passwords or other sensitive information used within the query. 

 

Action  

The defect may be mitigated now by removing the Community Dashboard Framework plugin from the software installation.

We recommend you upgrade to the latest Hitachi Vantara Pentaho Business Analytics Server release or Service Pack where this vulnerability is addressed. 

Please review the Pentaho End-of-Life policy to ensure you are up to date.

 


Internal Notes: (Non Customer View-able - Non Confidential)

This issue is logged under JIRA PPP-5717

Comments