Pentaho Data Integration and Analytics Community Dashboard Editor plugin versions before 10.2.0.4, including 9.3.0.x and 8.3.x, deserialize untrusted JSON data without constraining the parser to approved classes and methods.
History

Tue, 16 Dec 2025 17:15:00 +0000

Type Values Removed Values Added
First Time appeared Hitachi
Hitachi vantara Pentaho Business Analytics Server
Hitachi vantara Pentaho Data Integration And Analytics
Vendors & Products Hitachi
Hitachi vantara Pentaho Business Analytics Server
Hitachi vantara Pentaho Data Integration And Analytics

Tue, 16 Dec 2025 15:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Mon, 15 Dec 2025 23:00:00 +0000

Type Values Removed Values Added
Description Pentaho Data Integration and Analytics Community Dashboard Editor plugin versions before 10.2.0.4, including 9.3.0.x and 8.3.x, deserialize untrusted JSON data without constraining the parser to approved classes and methods.
Title Hitachi Vantara Pentaho Business Analytics Server - Deserialization of Untrusted Data
Weaknesses CWE-502
References
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: HITVAN

Published:

Updated: 2025-12-17T04:55:51.738Z

Reserved: 2025-08-18T18:06:38.505Z

Link: CVE-2025-9121

cve-icon Vulnrichment

Updated: 2025-12-16T14:38:33.274Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2025-12-15T23:15:57.590

Modified: 2025-12-16T14:10:11.300

Link: CVE-2025-9121

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2025-12-16T17:11:19Z