Cyber Resilience

CVE-2025-11159

Hitachi Vantara Pentaho Data Integration And Analytics ≤ 10.2.0.7

Published
13 May 2026
Modified
17 June 2026
Patch / advisory
CVSS Score v3.1 9.1
Click a component to see what it means
Raw vectorCVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
EPSS Score 0.0034 27th percentile
Risk Priority 58 floored blend · peak EPSS

Summary

CVE-2025-11159 is a critical-severity an unspecified weakness vulnerability in Hitachi Vantara Pentaho Data Integration And Analytics. Its CVSS base score is 9.1 (Critical).

Operationally, ranked at the 27th percentile by exploit likelihood (below the median); it is not currently listed in the CISA KEV catalog.

EU & UK References

Vulnerability Data

Hitachi Vantara Pentaho Data Integration & Analytics of all versions contain a JDBC driver for H2 databases which is vulnerable to external script execution when a new connection is created by a data source administrator.

CWE(s)

Related Threats

CVEs Like This One

CVE-2026-2253Same product: Hitachi Vantara Pentaho Data Integration And Analytics
CVE-2026-2254Same product: Hitachi Vantara Pentaho Data Integration And Analytics
CVE-2025-11158Same product: Hitachi Vantara Pentaho Data Integration And Analytics
CVE-2026-2255Same product: Hitachi Vantara Pentaho Data Integration And Analytics
CVE-2023-5617Same product: Hitachi Vantara Pentaho Data Integration And Analytics
CVE-2023-39986Same vendor: Hitachi
CVE-2024-21840Same vendor: Hitachi
CVE-2024-28982Same vendor: Hitachi
CVE-2025-1978Same vendor: Hitachi
CVE-2023-3517Same vendor: Hitachi

Affected Assets

hitachi
vantara pentaho data integration and analytics
≤ 10.2.0.7

Mitigating Controls

No mitigating controls mapped yet. The per-CVE control annotator has not reached this CVE.

References