Vulnerabilities in Hitachi Vantara

53 results
Vexday analysis

O portfólio de vulnerabilidades da Hitachi Vantara apresenta uma taxa de exploração ativa significativamente acima da média geral do catálogo CISA KEV — 8,4 vezes superior —, o que indica que, apesar do volume total relativamente baixo de 53 CVEs catalogadas, uma proporção elevada das falhas conhecidas já foi alvo de exploração real. A CVE mais crítica em atividade, CVE-2022-43769, registra EPSS de 0,9767, aproximando-se do valor máximo da escala e sinalizando altíssima probabilidade de exploração em ambiente produtivo. O tipo de falha mais recorrente é CWE-79 (Cross-Site Scripting), enquanto 3 vulnerabilidades possuem PoC pública disponível, reduzindo a barreira de entrada para agentes maliciosos. As 4 CVEs surgidas nos últimos 90 dias reforçam a necessidade de monitoramento contínuo, especialmente em ambientes onde a aplicação de patches pode ser operacionalmente complexa.

CVE-2022-43769HIGHHitachi Vantara Pentaho Business Analytics Server - Failure to Sanitize Special Elements into a Different Plane (Special Element Injection)EPSS 97.7%KEVCVE-2022-43939HIGHHitachi Vantara Pentaho Business Analytics Server - Use of Non-Canonical URL Paths for Authorization DecisionsEPSS 92.3%KEVCVE-2022-43938HIGHHitachi Vantara Pentaho Business Analytics Server - Improper Neutralization of Directives in Statically Saved Code ('Static Code Injection') EPSS 26.4%CVE-2022-43771MEDIUMHitachi Vantara Pentaho Business Analytics Server - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') EPSS 23.9%CVE-2022-43773HIGHHitachi Vantara Pentaho Business Analytics Server - Incorrect Permission Assignment for Critical Resource EPSS 22.2%CVE-2023-6538HIGHSystem Management Unit (SMU) versions prior to 14.8.7825.01, used to manage Hitachi Vantara NAS products is susceptible to unintended information disclosure via unprivileged access to SMU configuration backup data.EPSS 1.6%CVE-2025-0756CRITICALHitachi Vantara Pentaho Data Integration & Analytics - Improper Control of Resource Identifiers ('Resource Injection')EPSS 0.9%CVE-2024-5706HIGHHitachi Vantara Pentaho Data Integration & Analytics - Improper Control of Resource Identifiers ('Resource Injection')EPSS 0.7%CVE-2021-28052HIGHHitachi Content Platform Information Disclosure VulnerabilityEPSS 0.7%CVE-2023-3517HIGHHitachi Vantara Pentaho Data Integration & Analytics - Improper Control of Resource Identifiers ('Resource Injection')EPSS 0.6%CVE-2022-4815HIGHHitachi Vantara Pentaho Business Analytics Server - Deserialization of Untrusted Data EPSS 0.6%CVE-2022-43940HIGHHitachi Vantara Pentaho Business Analytics Server - Incorrect AuthorizationEPSS 0.6%CVE-2021-45448HIGHPentaho Business Analytics Server - Pentaho Analyzer plugin exposes a service endpoint for templates which allows a user supplied path to access resources that are out of bounds.EPSS 0.6%CVE-2023-5808HIGHSystem Management Unit (SMU) versions prior to 14.8.7825.01, used to manage Hitachi Vantara NAS products are susceptible to unintended information disclosure via unprivileged access to HNAS configuration backup and diagnostic data.EPSS 0.5%CVE-2022-43941HIGHHitachi Vantara Pentaho Business Analytics Server - Improper Restriction of XML External Entity Reference EPSS 0.5%CVE-2024-37361CRITICALHitachi Vantara Pentaho Business Analytics Server - Deserialization of Untrusted DataEPSS 0.5%CVE-2024-37359HIGHHitachi Vantara Pentaho Business Analytics Server – Server Side Request ForgeryEPSS 0.5%CVE-2024-5705HIGHHitachi Vantara Pentaho Business Analytics Server - Incorrect AuthorizationEPSS 0.5%CVE-2022-43770MEDIUMHitachi Vantara Pentaho Business Analytics Server - Incorrect AuthorizationEPSS 0.5%CVE-2025-24908MEDIUMHitachi Vantara Pentaho Data Integration & Analytics – Path TraversalEPSS 0.5%