A Java deserialisation vulnerability has been discovered in Jaspersoft Library. Improper handling of externally supplied data may allow attackers to execute arbitrary code remotely on systems that use the affected library
References
Configurations
Configuration 1 (hide)
|
History
No history.
Information
Published : 2025-09-16 17:15
Updated : 2025-10-14 15:06
NVD link : CVE-2025-10492
Mitre link : CVE-2025-10492
CVE.ORG link : CVE-2025-10492
JSON object : View
Products Affected
cloud
- jasperreports_studio
- jasperreports_io
- jasperreports_web_studio
- jasperreports_library
- jasperreports_server
CWE
CWE-502
Deserialization of Untrusted Data
