CVE-2025-9121 Details
Description
Pentaho Data Integration and Analytics Community Dashboard Editor plugin versions before 10.2.0.4, including 9.3.0.x and 8.3.x, deserialize untrusted JSON data without constraining the parser to approved classes and methods.
A deserialization vulnerability has been identified in the Hitachi Vantara Pentaho Data Integration and Analytics Community Dashboard Editor plugin. This issue affects versions prior to 10.2.0.4, including 9.3.0.x and 8.3.x. The vulnerability arises because the application deserializes untrusted JSON data without properly validating it, allowing for potential exploitation by manipulating the deserialization process.
Users are advised to remove the Community Dashboard Editor plugin from their installation. For those using Hitachi Vantara Pentaho Business Analytics Server, upgrading to the latest release or Service Pack where this vulnerability has been addressed is recommended. Please consult the Pentaho End-of-Life policy to ensure your version is current.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Dec 15, 2025CISA-ADP
Assessed Dec 17, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-502 | Deserialization of Untrusted Data | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| Hitachi Vantara Pentaho Data Integration | All versions |
CPE
Remediation
| |
| Hitachi Vantara Pentaho Analytics Community Dashboard Editor | All versions |
CPE
Remediation
| |
Change History
3 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Dec 15, 2025 | New CVE Received | [email protected] |
Volerion