Java Deserialisation Vulnerability in Jaspersoft Reports Library leads to Remote Code Execution (RCE), potentially allowing code execution on the affected system
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| Jaspersoft | JasperReports IO At-Scale | >= 0, <= 10.0.0CNA affecteddefault unaffected | |
| Jaspersoft | JasperReports IO Professional | >= 0, <= 10.0.0CNA affecteddefault unaffected | |
| Jaspersoft | JasperReports Library Community Edition | >= 0, <= 7.0.6CNA affecteddefault unaffected | |
| Jaspersoft | JasperReports Library Professional | >= 0, <= 10.0.0CNA affecteddefault unaffected | |
| Jaspersoft | JasperReports Server | >= 0, <= 10.0.0CNA affecteddefault unaffected |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.3 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.