CVE-2025-10492
16.09.2025, 17:15
A Java deserialisation vulnerability has been discovered in Jaspersoft Library. Improper handling of externally supplied data may allow attackers to execute arbitrary code remotely on systems that use the affected libraryEnginsight
| Vendor | Product | Version |
|---|---|---|
| cloud | jasperreports_io | 𝑥 ≤ 4.0.0 |
| cloud | jasperreports_io | 𝑥 ≤ 4.0.0 |
| cloud | jasperreports_library | 𝑥 ≤ 7.0.3 |
| cloud | jasperreports_library | 𝑥 ≤ 9.0.2 |
| cloud | jasperreports_server | 𝑥 ≤ 9.0.0 |
| cloud | jasperreports_studio | 𝑥 ≤ 7.0.3 |
| cloud | jasperreports_studio | 𝑥 ≤ 9.0.2 |
| cloud | jasperreports_web_studio | 𝑥 ≤ 3.0.1 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration