Home
CRITICAL: 9.1 CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:HDefault status
unaffected
1.0 (maven) before 10.2.0.7
affected
1.0 (maven) before 11.0
affected
Description
Hitachi Vantara Pentaho Data Integration & Analytics of all versions contain a JDBC driver for H2 databases which is vulnerable to external script execution when a new connection is created by a data source administrator.
Problem types
CWE-1395: Dependency on Vulnerable Third-Party Component
Product status
1.0 (maven) before 10.2.0.7
1.0 (maven) before 11.0
Credits
Nir Zadok (nirza) and Moshe Siman Tov Bustan from OX Security
References
support.pentaho.com/...-and-11-0-0-0-Impacted-CVE-2025-11159