Hitachi Vantara Pentaho Business Analytics Server versions before 9.4.0.1 and 9.3.0.2, including 8.3.x contain security restrictions using non-canonical URLs which can be circumvented.
https://www.securityweek.com/exploitation-long-known-for-most-of-cisas-latest-kev-additions/
https://www.infosecurity-magazine.com/news/cisa-govt-patch-exploited-cisco/
https://thehackernews.com/2025/03/cisco-hitachi-microsoft-and-progress.html