Description

Hitachi Vantara Pentaho Data Integration & Analytics versions before 10.2.0.6, including 9.3.x and 8.3.x, do not restrict Groovy scripts in new PRPT reports published by users, allowing insertion of arbitrary scripts and leading to a RCE.

INFO

Published Date :

2026-03-09T22:12:51.587Z

Last Modified :

2026-03-10T18:42:40.262Z

Source :

HITVAN
AFFECTED PRODUCTS

The following products are affected by CVE-2025-11158 vulnerability.

Vendors Products
Hitachi
  • Vantara Pentaho Data Integration And Analytics

CVSS Vulnerability Scoring System

Detailed values of each vector for above chart.
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality Impact
Integrity Impact
Availability Impact