CVE-2025-9122
Unknown
Unknown - Not Provided
Information Disclosure via Stack Trace Exposure in Hitachi Pentaho GetCdfResource Servlet
Publication date: 2025-12-15
Last updated on: 2025-12-15
Assigner: Hitachi Vantara
Description
Description
Hitachi Vantara Pentaho Data Integration and Analytics Community Dashboard Framework prior to versions 10.2.0.4, including 9.3.0.x and 8.3.x display the full server stack trace when encountering an error within the GetCdfResource servlet.
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| hitachi | pentaho_data_integration_and_analytics | 9.3.0 |
| hitachi | pentaho_data_integration_and_analytics | 8.3 |
| hitachi | pentaho_data_integration_and_analytics | 10.2.0.4 |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-209 | The product generates an error message that includes sensitive information about its environment, users, or associated data. |