CVE-2025-11159
Hitachi Vantara Pentaho Data Integration And Analytics ≤ 10.2.0.7
CVSS Score v3.1
9.1
Click a component to see what it means
Raw vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
EPSS Score
0.0034
27th percentile
Summary
CVE-2025-11159 is a critical-severity an unspecified weakness vulnerability in Hitachi Vantara Pentaho Data Integration And Analytics. Its CVSS base score is 9.1 (Critical).
Operationally, ranked at the 27th percentile by exploit likelihood (below the median); it is not currently listed in the CISA KEV catalog.
EU & UK References
- 🇪🇺 ENISA EUVD: EUVD-2025-209821
Vulnerability Data
Hitachi Vantara Pentaho Data Integration & Analytics of all versions contain a JDBC driver for H2 databases which is vulnerable to external script execution when a new connection is created by a data source administrator.
- CWE(s)
Related Threats
CVEs Like This One
CVE-2026-2253Same product: Hitachi Vantara Pentaho Data Integration And Analytics
CVE-2026-2254Same product: Hitachi Vantara Pentaho Data Integration And Analytics
CVE-2025-11158Same product: Hitachi Vantara Pentaho Data Integration And Analytics
CVE-2026-2255Same product: Hitachi Vantara Pentaho Data Integration And Analytics
CVE-2023-5617Same product: Hitachi Vantara Pentaho Data Integration And Analytics
CVE-2023-39986Same vendor: Hitachi
CVE-2024-21840Same vendor: Hitachi
CVE-2024-28982Same vendor: Hitachi
CVE-2025-1978Same vendor: Hitachi
CVE-2023-3517Same vendor: Hitachi
Affected Assets
hitachi
vantara pentaho data integration and analytics
≤ 10.2.0.7
Mitigating Controls
No mitigating controls mapped yet. The per-CVE control annotator has not reached this CVE.