Severity
High
Analysis Summary
CVE-2025-9121
Pentaho data integration and analytics community dashboard editor plugin versions before 10.2.0.4, including 9.3.0.x and 8.3.x, deserialize untrusted json data without constraining the parser to approved classes and methods.
Impact
- Gain Access
Indicators of Compromise
CVE
CVE-2025-9121
Affected Vendors
Hitachi
Affected Products
- Hitachi Vantara Pentaho Data Integration and Analytics 1.0
Remediation
Refer to Hitachi Pentaho Security Advisory for patch, upgrade, or suggested workaround information.

