Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

Hitachi Vantara — Vulnerabilities & Security Advisories 46

Browse all 46 CVE security advisories affecting Hitachi Vantara. AI-powered Chinese analysis, POCs, and references for each vulnerability.

Hitachi Vantara operates as a data management and analytics provider, offering software solutions for storage, virtualization, and cloud infrastructure. The company’s portfolio includes enterprise storage systems and data management platforms that serve critical business operations. Historical security records indicate approximately 46 Common Vulnerabilities and Exposures (CVEs), predominantly involving remote code execution, cross-site scripting, and privilege escalation flaws. These vulnerabilities often stem from web interface components and administrative APIs within their storage management software. While no single catastrophic breach has defined the brand’s public history, the recurring nature of these CVEs highlights persistent challenges in securing complex enterprise data environments. The firm generally addresses these issues through regular firmware updates and security advisories, maintaining a standard industry approach to vulnerability remediation without notable publicized data exfiltration incidents.

CVE IDTitleCVSSSeverityPublished
CVE-2023-1158 Hitachi Vantara Pentaho Business Analytics Server - Incorrect Authorization — Pentaho Business Analytics ServerCWE-863 4.3 Medium2023-05-24
CVE-2022-43770 Hitachi Vantara Pentaho Business Analytics Server - Incorrect Authorization — Pentaho Business Analytics ServerCWE-863 5.4 Medium2023-04-11
CVE-2022-3695 Hitachi Vantara Pentaho Business Analytics Server - Improper Neutralization of Input During Web Page Generation — Pentaho Business Analytics ServerCWE-79 6.5 Medium2023-04-11
CVE-2022-4771 Hitachi Vantara Pentaho Business Analytics Server - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') — Pentaho Business Analytics ServerCWE-79 5.4 Medium2023-04-03
CVE-2022-4770 Hitachi Vantara Pentaho Business Analytics Server - Generation of Error Message Containing Sensitive Information — Pentaho Business Analytics ServerCWE-209 4.3 Medium2023-04-03
CVE-2022-4769 Hitachi Vantara Pentaho Business Analytics Server - Generation of Error Message Containing Sensitive Information — Pentaho Business Analytics ServerCWE-209 4.3 Medium2023-04-03
CVE-2022-3960 Hitachi Vantara Pentaho Business Analytics Server - Improper Neutralization of Directives in Statically Saved Code ('Static Code Injection') — Pentaho Business Analytics ServerCWE-96 6.3 Medium2023-04-03
CVE-2022-43771 Hitachi Vantara Pentaho Business Analytics Server - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') — Pentaho Business Analytics ServerCWE-22 6.5 Medium2023-04-03
CVE-2022-43939 Hitachi Vantara Pentaho Business Analytics Server - Use of Non-Canonical URL Paths for Authorization Decisions — Pentaho Business Analytics ServerCWE-647 8.6 High2023-04-03
CVE-2022-43938 Hitachi Vantara Pentaho Business Analytics Server - Improper Neutralization of Directives in Statically Saved Code ('Static Code Injection') — Pentaho Business Analytics ServerCWE-96 8.8 High2023-04-03
CVE-2022-43773 Hitachi Vantara Pentaho Business Analytics Server - Incorrect Permission Assignment for Critical Resource — Pentaho Business Analytics ServerCWE-732 8.8 High2023-04-03
CVE-2022-43769 Hitachi Vantara Pentaho Business Analytics Server - Failure to Sanitize Special Elements into a Different Plane (Special Element Injection) — Pentaho Business Analytics ServerCWE-74 8.8 High2023-04-03
CVE-2021-45448 Pentaho Business Analytics Server - Pentaho Analyzer plugin exposes a service endpoint for templates which allows a user supplied path to access resources that are out of bounds. — Pentaho Business Analytics ServerCWE-22 7.1 High2022-11-02
CVE-2021-45447 Pentaho Business Analytics Server - With the Data Lineage feature enabled, the system transmits database passwords in clear text — Pentaho Business Analytics ServerCWE-319 7.7 High2022-11-02
CVE-2021-45446 Pentaho Business Analytics Server - Exposure of Information Through Directory Listing — Pentaho Business Analytics ServerCWE-548 5.0 Medium2022-11-02
CVE-2021-28052 Hitachi Content Platform Information Disclosure Vulnerability — Hitachi Content PlatformCWE-264 7.5 High2022-09-26

This page lists every published CVE security advisory associated with Hitachi Vantara. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.