Intelligence View
⚡ tsecurity.de Intelligence
CVE-2025-11159 | Hitachi Vantara Pentaho Data Integration and Analytics up to 10.x JDBC Driver vulnerable third-party component
A vulnerability was found in Hitachi Vantara Pentaho Data Integration and Analytics up to 10.x. It has been declared as problematic. This issue affects some…
A vulnerability was found in Hitachi Vantara Pentaho Data Integration and Analytics up to 10.x. It has been declared as problematic. This issue affects some unknown processing of the component JDBC Driver. Such manipulation leads to dependency on vulnerable third-party component.
This vulnerability is listed as CVE-2025-11159. The attack may be performed from remote. There is no available exploit.
It is recommended to upgrade the affected component.
This vulnerability is listed as CVE-2025-11159. The attack may be performed from remote. There is no available exploit.
It is recommended to upgrade the affected component.
Cyber Threat Intelligence & Forensik
ATT&CK-Navigator · IoC-Radar · Exploit-Belege
Compliance, SLA & Vendor Adherence
Advisory-Prüfung · Score-Einordnung · Fristen
CVSS 9.1CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
Impact: 6.05 | Exploitability: 2.29
AVN
Netzwerk (Remote)
Aus der Ferne über das Internet ohne Vorbedingungen exploitbar.
ACL
Niedrig (Low)
Wiederholbar und deterministisch ohne spezielle Race Conditions ausnutzbar.
PRH
Hoch (Administrator / Root)
Erfordert privilegierte administrative Zugriffsrechte.
UIN
Keine (Zero-Click)
Autonom ohne menschliches Zutun ausführbar (Zero-Click Exploitation).
SC
Verändert (Scope Changed)
Kann auf übergeordnete Systeme oder Hypervisor/Cloud-Ebene übergreifen (Sandbox Escape).
CH
Hoch (Totaler Abfluss)
Vollständiger Zugriff auf alle sensiblen Datenbank- und Speicherinhalte.
IH
Hoch (Volle Manipulation)
Vollständige Modifikation von Dateien, Parametern oder Ausführung von Code.
AH
Hoch (Totaler Ausfall / DoS)
Dienst oder Server wird komplett unbrauchbar (Denial of Service).
NVD Primärbewertung & CISA SSVCCVE-2025-11159
NVD: AnalyzedNVD 7.2 · HIGH
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
NVD-Datenstand: 30.09.2026, 22:10 UTC
Abweichung zum Hersteller-Sekundärscore (EUVD-Karte oben): 9.1
Ausnutzung beobachtet: Nein Automatisierbar: Nein Technischer Impact: Total
CISA-SSVC-Triage (vulnrichment)CVE-2025-11159
Exploitation: none (Keine bekannte Ausnutzung)Automatable: no (Nicht automatisierbar)Technical Impact: total (Vollständig)
Quelle: CISA-ADP vulnrichment · Stand 2026-05-13T14:44:30.743315Z · CISA Coordinator
Advisory Radar
In herstellerseitiger Prüfung
Hersteller-Sicherheitsmeldungen & Patch-Status
Handlungsempfehlung für Administratoren
Hersteller-Advisory noch nicht formal hinterlegt. Regelmäßiges Re-Scanning der CTI-Quellen anberaumt.
Referenzen aus der Primärquelle („Verifiziert" nur bei Hersteller-Domäne):
-
Web Referencesupport.pentaho.com