Hitachi Vantara
First CVE: Nov 2, 2022Active for: 4 years
52
CVEs Published
More CVEs Published than 59% of tracked CNAs
10.4
Avg CVEs / Year
More Avg CVEs / Year than 55% of tracked CNAs
6.8
Avg CVSS Score
Higher Avg CVSS Score than 35% of tracked CNAs
3.8%
In CISA KEV
Higher KEV Rate than 95% of tracked CNAs
Trends Over Time
The number and severity of CVEs published by Hitachi Vantara over time
Volume of CVEsAvg CVSS Base Score
First CVE
Nov 2, 2022
3 years ago
Most Recent CVE
May 27, 2026
58 days ago
Top CVEs
All CVEs published by Hitachi Vantara as a CNA, regardless of affected vendor or product.
52 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2022-43939CRITICAL Hitachi Vantara Pentaho Business Analytics Server versions before 9.4.0.1 and 9.3.0.2, including 8.3.x contain security restrictions using non-canonical URLs which can be circumven | Apr 3, 2023 | 9.8 | 99 | YES | YES |
CVE-2022-43769HIGH Hitachi Vantara Pentaho Business Analytics Server prior to versions 9.4.0.1 and 9.3.0.2, including 8.3.x allow certain web services to set property values which contain Spring temp | Apr 3, 2023 | 7.2 | 98 | YES | YES |
CVE-2022-43938HIGH
Hitachi Vantara Pentaho Business Analytics Server prior to versions 9.4.0.1 and 9.3.0.2, including 8.3.x cannot allow a system administrator to disable scripting capabilities of P | Apr 3, 2023 | 8.8 | 41 | NO | NO |
CVE-2022-43773HIGH
Hitachi Vantara Pentaho Business Analytics Server prior to versions 9.4.0.1 and 9.3.0.2, including 8.3.x is installed with a sample HSQLDB data source configured with stored proce | Apr 3, 2023 | 8.8 | 37 | NO | NO |
CVE-2026-2253HIGH Hitachi Vantara Pentaho Data Integration & Analytics versions before 10.2.0.7 and 11.0.0.0, including 9.3.x and 8.3.x, does not prevent certain XML parsers from resolving external | May 27, 2026 | 7.7 | 33 | NO | NO |
CVE-2022-43771MEDIUM
Hitachi Vantara Pentaho Business Analytics Server versions before 9.4.0.0 and 9.3.0.1, including 8.3.x, using the Pentaho Data Access plugin exposes a service endpoint for CSV imp | Apr 3, 2023 | 6.5 | 32 | NO | NO |
CVE-2025-11158CRITICAL Hitachi Vantara Pentaho Data Integration & Analytics versions before 10.2.0.6, including 9.3.x and 8.3.x, do not restrict Groovy scripts in new PRPT reports published by users, all | Mar 10, 2026 | 9.1 | 30 | NO | NO |
CVE-2025-11159HIGH Hitachi Vantara Pentaho Data Integration & Analytics of all versions contain a JDBC driver for H2 databases which is vulnerable to external script execution when a new connection i | May 13, 2026 | 7.2 | 29 | NO | NO |
CVE-2024-37361CRITICAL The application deserializes untrusted data without sufficiently verifying that the resulting data will be valid. (CWE-502)
Hitachi Vantara Pentaho Business Analytics Serve | Feb 20, 2025 | 9.9 | 29 | NO | NO |
CVE-2026-2254MEDIUM Hitachi Vantara Pentaho Data Integration & Analytics versions before 10.2.0.6 and 11.0.0.0, including 9.3.x and 8.3.x, does not apply ACLs on certain API endpoints related to platf | May 27, 2026 | 6.3 | 27 | NO | NO |
CVE Severity & Scoring
Severity distribution of CVEs published by this CNA52 CVEs
60%
33%
Severity distribution among all CVEs352,231 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local1 (1.9%)
Network51 (98.1%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low49 (94.2%)
High3 (5.8%)
Unknown0 (0.0%)
User Interaction
None48 (92.3%)
Unknown0 (0.0%)
Required4 (7.7%)
Privileges Required
Low28 (53.8%)
High13 (25.0%)
None11 (21.2%)
Unknown0 (0.0%)
Exploit Exposure
Signals from CVEs in this cna scope (52 CVEs).
CISA KEV
2 CVEs
3.8% of CVEs· 95th percentile
Metasploit
2 CVEs
3.8% of CVEs· 96th percentile
Nuclei
2 CVEs
3.8% of CVEs· 91st percentile
ExploitDB
3 CVEs
5.8% of CVEs· 96th percentile
Social Chatter
An overview of all social media posts that mention a CVE ID published by Hitachi Vantara as a CNA.
Media Mentions
Media articles that mention a CVE ID published by Hitachi Vantara as a CNA — matched by CVE ID, not by organization name.