CVE-2025-9122
Information Disclosure via Stack Trace Exposure in Hitachi Pentaho GetCdfResource Servlet
Publication date: 2025-12-15
Last updated on: 2025-12-15
Assigner: Hitachi Vantara
Description
Description
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| hitachi | pentaho_data_integration_and_analytics | 9.3.0 |
| hitachi | pentaho_data_integration_and_analytics | 8.3 |
| hitachi | pentaho_data_integration_and_analytics | 10.2.0.4 |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-209 | The product generates an error message that includes sensitive information about its environment, users, or associated data. |
Attack-Flow Graph
AI Powered Q&A
How can this vulnerability impact me? :
The vulnerability can lead to information disclosure by exposing the full server stack trace during errors. This information can help attackers understand the internal workings of the server, potentially aiding in further attacks or exploitation.
Can you explain this vulnerability to me?
This vulnerability occurs in Hitachi Vantara Pentaho Data Integration and Analytics Community Dashboard Framework versions prior to 10.2.0.4, including 9.3.0.x and 8.3.x. When an error happens within the GetCdfResource servlet, the full server stack trace is displayed. This means sensitive internal server information is exposed to users or attackers.