CVE-2022-43769: Hitachi Pentaho Business Analytics Server – Remote Code Execution

CVE-2022-43769: Hitachi Pentaho Business Analytics Server - Remote Code Execution-渗透云记 - 专注于网络安全与技术分享
CVE-2022-43769: Hitachi Pentaho Business Analytics Server – Remote Code Execution
此内容为付费阅读,请付费后查看
100积分
付费阅读

漏洞标题

CVE-2022-43769: Hitachi Pentaho Business Analytics Server – Remote Code Execution

漏洞描述

Hitachi Pentaho Business Analytics Server prior to versions 9.4.0.1 and 9.3.0.2, including 8.3.x, is susceptible to remote code execution via server-side template injection. Certain web services can set property values which contain Spring templates that are interpreted downstream, thereby potentially enabling an attacker to execute malware, obtain sensitive information, modify data, and/or perform unauthorized operations without entering necessary credentials.

PoC代码

© 版权声明
THE END
喜欢就支持一下吧
点赞0 分享